Access Watch: Security and Traffic Insights Security & Risk Analysis

wordpress.org/plugins/access-watch

Understand precisely the robot traffic on your website and take actions to improve performance and security.

30 active installs v2.0.0-end-of-life PHP + WP 4.0+ Updated Nov 26, 2018
analyticsdashboardsecurityspamstatistics
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Access Watch: Security and Traffic Insights Safe to Use in 2026?

Generally Safe

Score 85/100

Access Watch: Security and Traffic Insights has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "access-watch" plugin v2.0.0-end-of-life exhibits a generally good security posture based on the static analysis and vulnerability history. The absence of known CVEs, critical taint flows, and dangerous functions suggests a well-developed codebase concerning these aspects. Furthermore, the plugin correctly utilizes prepared statements for all SQL queries and has capability checks in place, demonstrating adherence to secure coding practices for data handling and authorization.

However, there are notable areas of concern. The presence of cron events without explicit mention of authentication checks raises a potential risk if these events trigger sensitive actions. More critically, the output escaping is only 50% properly handled, indicating a potential for cross-site scripting (XSS) vulnerabilities. The lack of nonce checks, while not directly leading to a deduced deduction based on the current data, is a common security measure for AJAX operations that is entirely absent here.

Given that this version is end-of-life, the lack of recorded vulnerabilities in the past might be less a reflection of inherent security and more a consequence of a lack of active security auditing and patching on an outdated version. The primary risks lie in the XSS potential from unescaped output and the theoretical risk associated with cron events that may not be adequately secured.

Key Concerns

  • Output escaping is only 50% properly handled
  • 0 Nonce checks on entry points
  • 2 cron events without explicit auth checks mentioned
Vulnerabilities
None known

Access Watch: Security and Traffic Insights Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Access Watch: Security and Traffic Insights Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
4
4 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

50% escaped8 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
access_watch_dashboard (index.php:267)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Access Watch: Security and Traffic Insights Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filterstatus_headerincludes\http-response-code.php:19
filterpre_http_requestincludes\http-time.php:13
filterhttp_responseincludes\http-time.php:21
actioninitincludes\http-time.php:43
actionaccess_watch_cleanindex.php:56
actionadmin_menuindex.php:191
actionadmin_enqueue_scriptsindex.php:357
actionadmin_noticesindex.php:384
actionadmin_enqueue_scriptsindex.php:394
actionwp_login_failedindex.php:541
actionwp_loginindex.php:557
actionwpcf7_submitindex.php:573

Scheduled Events 2

access_watch_clean
access_watch_post_activation
Maintenance & Trust

Access Watch: Security and Traffic Insights Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 26, 2018
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings12
Active installs30
Developer Profile

Access Watch: Security and Traffic Insights Developer Profile

François Hodierne

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Access Watch: Security and Traffic Insights

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/access-watch/assets/css/style.css/wp-content/plugins/access-watch/assets/js/admin.js
Script Paths
/wp-content/plugins/access-watch/assets/js/admin.js
Version Parameters
access-watch/assets/css/style.css?ver=access-watch/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
access-watch-dashboard-wrapaccess-watch-about-wrap
Data Attributes
data-access-watch-api-keydata-access-watch-site-id
JS Globals
AccessWatchAdmin
REST Endpoints
/wp-json/access-watch/v1/settings
FAQ

Frequently Asked Questions about Access Watch: Security and Traffic Insights