adBlock Alerter Security & Risk Analysis

wordpress.org/plugins/adblock-alerter

Detects if a user is using adBlock, adBlock Plus or any other software that might be disabling ads on your website and prompts them to disable it.

10 active installs v0.8.5 PHP + WP 3.0.1+ Updated Jun 6, 2014
adadblockadblock-plusblockpro
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is adBlock Alerter Safe to Use in 2026?

Generally Safe

Score 85/100

adBlock Alerter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'adblock-alerter' plugin v0.8.5 exhibits a concerning security posture primarily due to a complete lack of output escaping, indicating a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While the static analysis reports no dangerous functions, SQL injection vulnerabilities, file operations, external HTTP requests, or a significant attack surface, the fact that 100% of output is unescaped is a critical flaw. Taint analysis revealing two flows with unsanitized paths further reinforces this concern, even though they are not classified as critical or high severity. The absence of any recorded vulnerabilities in its history might suggest a lack of past exploitation or discovery, but it does not negate the inherent risks identified in the current code. The plugin's strengths lie in its absence of common attack vectors like raw SQL queries and a large, unprotected attack surface. However, the severe lack of output escaping is a fundamental security deficiency that requires immediate attention.

Key Concerns

  • 100% of output is unescaped
  • Taint analysis found unsanitized paths
Vulnerabilities
None known

adBlock Alerter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

adBlock Alerter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped10 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<preview> (includes\preview.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

adBlock Alerter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuadblock_alerter.php:17
actionwp_headadblock_alerter.php:18
actionwp_footeradblock_alerter.php:19
actionadmin_initadblock_alerter.php:20
Maintenance & Trust

adBlock Alerter Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJun 6, 2014
PHP min version
Downloads4K

Community Trust

Rating66/100
Number of ratings9
Active installs10
Developer Profile

adBlock Alerter Developer Profile

SuperWebDev

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect adBlock Alerter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/adblock-alerter/css/style.css/wp-content/plugins/adblock-alerter/css/settings.css/wp-content/plugins/adblock-alerter/js/init.js/wp-content/plugins/adblock-alerter/js/upload.js
Script Paths
/wp-content/plugins/adblock-alerter/js/init.js/wp-content/plugins/adblock-alerter/js/upload.js
Version Parameters
adblock-alerter/css/style.css?ver=adblock-alerter/css/settings.css?ver=adblock-alerter/js/init.js?ver=adblock-alerter/js/upload.js?ver=

HTML / DOM Fingerprints

CSS Classes
adb_settingsadb_titleadb_contentimage_locationilsideinner_side
Data Attributes
data-il
JS Globals
blocker
FAQ

Frequently Asked Questions about adBlock Alerter