
Admin Allow by IP Security & Risk Analysis
wordpress.org/plugins/admin-allow-by-ipProtect your admin form hackers!. You can allow your wp-admin for specific IP(s).
Is Admin Allow by IP Safe to Use in 2026?
Generally Safe
Score 85/100Admin Allow by IP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'admin-allow-by-ip' v1.0.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate good practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of output escaping. The lack of file operations, external HTTP requests, and the absence of identified taint flows further bolster its security. The plugin's vulnerability history is also clean, with no recorded CVEs, which suggests a history of secure development or diligent patching. However, the complete absence of nonce checks and capability checks across all entry points, while not explicitly problematic due to the limited attack surface, represents a potential weakness if the plugin were to evolve and introduce new entry points without corresponding security measures. In conclusion, this plugin appears to be very secure in its current state, with its limited functionality and good coding practices mitigating potential risks. The primary area for caution would be future development potentially introducing unaddressed security checks.
Key Concerns
- No nonce checks detected
- No capability checks detected
Admin Allow by IP Security Vulnerabilities
Admin Allow by IP Code Analysis
Output Escaping
Admin Allow by IP Attack Surface
WordPress Hooks 9
Maintenance & Trust
Admin Allow by IP Maintenance & Trust
Maintenance Signals
Community Trust
Admin Allow by IP Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Sucuri Security – Auditing, Malware Scanner and Security Hardening
sucuri-scanner
The Sucuri WordPress Security plugin is a security toolset for security integrity monitoring, malware detection and security hardening.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
Admin Allow by IP Developer Profile
11 plugins · 700 total installs
How We Detect Admin Allow by IP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/admin-allow-by-ip/css/admin-allow-by-ip-admin.css/wp-content/plugins/admin-allow-by-ip/js/admin-allow-by-ip-admin.jsjs/admin-allow-by-ip-admin.jsadmin-allow-by-ip-admin.css?ver=admin-allow-by-ip-admin.js?ver=