Onion Service by Adam Szokol Security & Risk Analysis

wordpress.org/plugins/adamszokol-onion-service

A focused plugin designed to enable Onion Service & Mapping support for your WordPress site.

0 active installs v1.0.2 PHP 7.4+ WP 5.8+ Updated Dec 22, 2025
multisiteonionprivacysecuritytor
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Onion Service by Adam Szokol Safe to Use in 2026?

Generally Safe

Score 100/100

Onion Service by Adam Szokol has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The adamszokol-onion-service plugin version 1.0.2 demonstrates a generally good security posture based on the provided static analysis. It boasts a small attack surface with all entry points being protected by either authentication or capability checks. The absence of dangerous functions, raw SQL queries, and external HTTP requests are positive indicators. The plugin also performs a high percentage of output escaping, which is crucial for preventing cross-site scripting vulnerabilities. Taint analysis shows no critical or high severity flows with unsanitized paths, further reinforcing its secure coding practices in this area.

While the plugin has no recorded vulnerability history and implements strong security checks on its AJAX handlers, there are a few areas that warrant consideration. The presence of file operations, though not inherently insecure, could be a vector for attacks if not handled with extreme care. Furthermore, the 19% of outputs that are not properly escaped represent a potential weakness that could be exploited. Without specific details on the nature of these unescaped outputs, it's difficult to quantify the exact risk, but it's a common source of XSS vulnerabilities.

In conclusion, adamszokol-onion-service v1.0.2 appears to be a well-developed plugin with a strong emphasis on security fundamentals. The lack of historical vulnerabilities and the robust implementation of authentication and sanitization are commendable. However, the small percentage of unescaped output and the presence of file operations, even if seemingly benign, are minor concerns that could be addressed to further strengthen its security.

Key Concerns

  • Outputs not properly escaped
Vulnerabilities
None known

Onion Service by Adam Szokol Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Onion Service by Adam Szokol Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
52 escaped
Nonce Checks
6
Capability Checks
8
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped64 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<adamszokol-onion-service> (adamszokol-onion-service.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Onion Service by Adam Szokol Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_adam_search_sitesadamszokol-onion-service.php:63
authwp_ajax_adam_search_sitestrunk\adamszokol-onion-service.php:63
WordPress Hooks 10
actionplugins_loadedadamszokol-onion-service.php:44
actionadmin_enqueue_scriptsadamszokol-onion-service.php:59
actionadmin_post_adam_saveadamszokol-onion-service.php:61
actionadmin_post_adam_deleteadamszokol-onion-service.php:62
actiontemplate_redirectadamszokol-onion-service.php:64
actionplugins_loadedtrunk\adamszokol-onion-service.php:44
actionadmin_enqueue_scriptstrunk\adamszokol-onion-service.php:59
actionadmin_post_adam_savetrunk\adamszokol-onion-service.php:61
actionadmin_post_adam_deletetrunk\adamszokol-onion-service.php:62
actiontemplate_redirecttrunk\adamszokol-onion-service.php:64
Maintenance & Trust

Onion Service by Adam Szokol Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 22, 2025
PHP min version7.4
Downloads251

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Onion Service by Adam Szokol Developer Profile

Adam Szokol

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Onion Service by Adam Szokol

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/adamszokol-onion-service/css/admin-style.css/wp-content/plugins/adamszokol-onion-service/js/admin-script.js
Script Paths
/wp-content/plugins/adamszokol-onion-service/js/admin-script.js
Version Parameters
adamszokol-onion-service/css/admin-style.css?ver=1.0.2adamszokol-onion-service/js/admin-script.js?ver=1.0.2

HTML / DOM Fingerprints

Data Attributes
id="adam_onion_run_setup"id="adam_onion_service_settings"id="adam_blog_search"id="adam_search_results"id="adam_onion_url"name="adam_onion_service_settings[onion_url]"+11 more
JS Globals
adamOnionData
FAQ

Frequently Asked Questions about Onion Service by Adam Szokol