3rd Party Request Manager Security & Risk Analysis

wordpress.org/plugins/3rd-party-request-manager

Get hold on GDPR and privacy unfriendly 3rd party requests. Block & Logs all external resource requests like images, scripts, CSS, fonts, etc.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Apr 15, 2025
3rd-party-requestgdprmonitorprivacy
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is 3rd Party Request Manager Safe to Use in 2026?

Generally Safe

Score 100/100

3rd Party Request Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The 3rd-party-request-manager plugin, version 1.0.0, exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, file operations, external HTTP requests, and the complete sanitization of all analyzed output are significant strengths. The presence of a nonce check and the high percentage of SQL queries utilizing prepared statements indicate good development practices aimed at preventing common web vulnerabilities.

However, a key concern arises from the complete lack of capability checks across all identified entry points, including the REST API route and any potential AJAX handlers (though none were found to be unprotected directly). While the current analysis shows no unsanitized taint flows or known vulnerabilities, the absence of capability checks means that any functionality exposed, however small, could theoretically be accessed by any authenticated user, regardless of their role or permissions. This is a notable weakness that could be exploited if the plugin's functionality were to expand or if a vulnerability were introduced in the future.

The plugin's vulnerability history is completely clean, with no recorded CVEs. This, coupled with the positive code signals, suggests a well-maintained and relatively secure plugin at this version. Nevertheless, the lack of capability checks represents a latent risk that should be addressed to ensure robust security as the plugin evolves.

Key Concerns

  • No capability checks on entry points
Vulnerabilities
None known

3rd Party Request Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

3rd Party Request Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
5 prepared
Unescaped Output
0
107 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

56% prepared9 total queries

Output Escaping

100% escaped107 total outputs
Attack Surface

3rd Party Request Manager Attack Surface

Entry Points1
Unprotected0

REST API Routes 1

POST/wp-json/nsc-tppm/v1/interceptapi\class-api.php:23
WordPress Hooks 9
actionadmin_enqueue_scriptsadmin\actions.php:11
actionadmin_menuadmin\actions.php:12
actionadmin_initadmin\actions.php:15
actionnsc3ppm_daily_cleanupadmin\actions.php:18
actionnsc3ppm_daily_domain_notificationadmin\actions.php:19
actionrest_api_initapi\actions.php:8
actionwp_enqueue_scriptsfrontend\actions.php:8
actionsend_headersfrontend\actions.php:9
actionwpmu_new_bloginstall\actions.php:11

Scheduled Events 2

nsc3ppm_daily_cleanup
nsc3ppm_daily_domain_notification
Maintenance & Trust

3rd Party Request Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 15, 2025
PHP min version7.4
Downloads491

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

3rd Party Request Manager Developer Profile

Nikel

5 plugins · 40K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
406 days
View full developer profile
Detection Fingerprints

How We Detect 3rd Party Request Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/3rd-party-request-manager/admin/assets/css/nsc3ppm.css/wp-content/plugins/3rd-party-request-manager/admin/assets/js/bootstrap.bundle.min.js
Script Paths
/wp-content/plugins/3rd-party-request-manager/admin/assets/js/bootstrap.bundle.min.js
Version Parameters
3rd-party-request-manager/admin/assets/css/nsc3ppm.css?ver=3rd-party-request-manager/admin/assets/js/bootstrap.bundle.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
nsc3ppm.cssstatusPillbadgerounded-pilltext-bg-successtext-bg-danger
Data Attributes
data-bs-toggledata-bs-target
FAQ

Frequently Asked Questions about 3rd Party Request Manager