Addiction Recovery Connector Security & Risk Analysis

wordpress.org/plugins/addiction-recovery-connector

The Addiction Recovery Connector plugin connects your WordPress site with the Addiction Recovery content publishing portal which allows us to easily s …

10 active installs v1.1.5 PHP 7.0+ WP 3.5+ Updated Aug 25, 2023
blogcontent-publishingpost-schedulingpublishing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Addiction Recovery Connector Safe to Use in 2026?

Generally Safe

Score 85/100

Addiction Recovery Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The addiction-recovery-connector plugin, version 1.1.5, exhibits a mixed security posture. While the absence of known CVEs and dangerous functions is a positive sign, several critical security concerns are present in the static analysis results. A significant portion of the attack surface, specifically 2 AJAX handlers and 1 REST API route, are not protected by authentication checks or permission callbacks. This lack of authorization exposes these entry points to potential unauthorized access and manipulation. Furthermore, the taint analysis reveals flows with unsanitized paths, indicating potential risks related to handling user-supplied data, although no critical or high-severity issues were identified in this area. The code also shows a moderate level of output escaping and a substantial number of SQL queries, with a concerning percentage not utilizing prepared statements, which can lead to SQL injection vulnerabilities. The presence of an outdated bundled jQuery library is another weakness. Overall, the plugin has strengths in its lack of historical vulnerabilities and avoidance of clearly dangerous functions, but the unprotected entry points and potential for SQL injection and data sanitization issues present notable risks that require immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API route
  • SQL queries without prepared statements
  • Flows with unsanitized paths
  • Bundled outdated jQuery library
  • Lack of nonce checks on AJAX handlers
Vulnerabilities
None known

Addiction Recovery Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Addiction Recovery Connector Release Timeline

v1.1.5Current
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
Code Analysis
Analyzed Mar 17, 2026

Addiction Recovery Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
5 prepared
Unescaped Output
55
80 escaped
Nonce Checks
0
Capability Checks
3
File Operations
1
External Requests
1
Bundled Libraries
1

Bundled Libraries

jQuery2.1.3

SQL Query Safety

33% prepared15 total queries

Output Escaping

59% escaped135 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
send_posts_row (inc\creator-instagram.php:229)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Addiction Recovery Connector Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 2

authwp_ajax_ar_get_pageinc\creator-instagram.php:10
noprivwp_ajax_ar_get_pageinc\creator-instagram.php:11

REST API Routes 1

POST/wp-json/ar/v1/validate-tokensinc\token-validation-endpoint.php:9

Shortcodes 1

[ar_author_information] inc\creator-reviewer.php:29
WordPress Hooks 46
actionrest_api_initcustom_routes\class.main.php:571
actionadmin_menuinc\admin.php:2
filterthe_contentinc\creator-anchors.php:11
actionplugin_loadedinc\creator-instagram.php:8
actiontemplate_redirectinc\creator-instagram.php:9
actionar_show_instagram_feedinc\creator-instagram.php:12
actionar_display_feed_headerinc\creator-instagram.php:13
actionar_display_feed_footerinc\creator-instagram.php:14
actionwp_enqueue_scriptsinc\creator-instagram.php:60
filterpre_get_document_titleinc\creator-instagram.php:61
actionwp_enqueue_scriptsinc\creator-related.php:16
actionwp_enqueue_scriptsinc\creator-related.php:201
actionwp_enqueue_scriptsinc\creator-related.php:383
actionwidgets_initinc\creator-related.php:457
actioninitinc\creator-reviewer.php:9
actionadd_meta_boxes_ar_reviewer_hinc\creator-reviewer.php:10
actionsave_post_ar_reviewer_hinc\creator-reviewer.php:11
actionadd_meta_boxesinc\creator-reviewer.php:12
actionadd_meta_boxesinc\creator-reviewer.php:13
actionsave_postinc\creator-reviewer.php:14
actionsave_post_pageinc\creator-reviewer.php:15
filterthe_contentinc\creator-reviewer.php:18
actionwp_headinc\creator-reviewer.php:19
actiontemplate_redirectinc\creator-reviewer.php:20
filtersingle_templateinc\creator-reviewer.php:21
filterpost_type_linkinc\creator-reviewer.php:22
actionpre_get_postsinc\creator-reviewer.php:23
actionshow_user_profileinc\creator-reviewer.php:24
actionedit_user_profileinc\creator-reviewer.php:25
actionpersonal_options_updateinc\creator-reviewer.php:26
actionedit_user_profile_updateinc\creator-reviewer.php:27
actionwp_headinc\creator-reviewer.php:28
actionwp_enqueue_scriptsinc\creator-reviewer.php:30
actionwp_footerinc\creator-reviewer.php:31
actionar_show_reviewer_listinc\creator-reviewer.php:32
actionar_show_authors_listinc\creator-reviewer.php:33
actionar_display_page_headerinc\creator-reviewer.php:34
actionar_display_page_footerinc\creator-reviewer.php:35
filterfinal_outputinc\creator-reviewer.php:258
filterget_the_archive_titleinc\creator-reviewer.php:294
filterpre_get_document_titleinc\creator-reviewer.php:908
actionpre_post_updateinc\hooks.php:2
actionpost_updatedinc\hooks.php:97
actioninitinc\hooks.php:135
actionrest_api_initinc\token-validation-endpoint.php:5
actiontemplate_redirectplugin.php:53
Maintenance & Trust

Addiction Recovery Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 25, 2023
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Addiction Recovery Connector Developer Profile

addictionrecovery21

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Addiction Recovery Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addiction-recovery-connector/assets/addiction-instagram-creator.css/wp-content/plugins/addiction-recovery-connector/assets/image-loader.js/wp-content/plugins/addiction-recovery-connector/assets/jquery.lazyload.min.js/wp-content/plugins/addiction-recovery-connector/assets/addiction-instagram-creator.js/wp-content/plugins/addiction-recovery-connector/assets/jquery-2.1.3.min.js
Script Paths
/wp-content/plugins/addiction-recovery-connector/assets/addiction-instagram-creator.js/wp-content/plugins/addiction-recovery-connector/assets/image-loader.js/wp-content/plugins/addiction-recovery-connector/assets/jquery.lazyload.min.js/wp-content/plugins/addiction-recovery-connector/assets/jquery-2.1.3.min.js
Version Parameters
addiction-recovery-connector/assets/addiction-instagram-creator.css?ver=addiction-recovery-connector/assets/addiction-instagram-creator.js?ver=addiction-recovery-connector/assets/image-loader.js?ver=addiction-recovery-connector/assets/jquery.lazyload.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
ar-connect-feed-rowar-connect-entry-1ar-connect-imagear-connect-instagram-creator
Data Attributes
data-original
JS Globals
ADDICTION_RECOVERY_PLUGIN_DIR_PATH
REST Endpoints
/wp-json/addiction-recovery-connector/v1/token-validation
FAQ

Frequently Asked Questions about Addiction Recovery Connector