Admin Bug Report Security & Risk Analysis

wordpress.org/plugins/admin-bug-report

A small plugin to help your WordPress clients report bugs and issues directly from the admin.

0 active installs v2.1.0 PHP + WP 4.3+ Updated Feb 6, 2025
adminbugissuereportscreenshot
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Admin Bug Report Safe to Use in 2026?

Generally Safe

Score 92/100

Admin Bug Report has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'admin-bug-report' plugin version 2.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output. There are no recorded vulnerabilities (CVEs) or critical/high severity taint flows, suggesting a generally well-written codebase with respect to data handling and potential injection attacks.

However, a significant concern arises from the static analysis, which reveals a single AJAX handler that lacks any authentication checks. This creates a direct and unprotected entry point into the plugin's functionality. While there are no known vulnerabilities in its history, this unprotected AJAX endpoint presents a potential vector for attackers to exploit if any logic flaw or unintended functionality exists within that handler. The absence of capability checks is also noteworthy, as it means this unprotected entry point might be accessible by any logged-in user, regardless of their role or permissions.

In conclusion, the plugin's strengths lie in its secure handling of database interactions and output sanitization. The primary weakness is the exposed AJAX endpoint, which, despite the lack of historical vulnerabilities, represents a clear security risk due to its unauthenticated nature. This single vulnerability could be exploited if the AJAX handler performs sensitive actions.

Key Concerns

  • AJAX handler without auth checks
  • Missing capability checks
Vulnerabilities
None known

Admin Bug Report Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Admin Bug Report Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface
1 unprotected

Admin Bug Report Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_admin_bug_report_submitincludes\class-admin-bug-report.php:165
WordPress Hooks 8
filterwp_mail_content_typeadmin\class-admin-bug-report-admin.php:393
actionplugins_loadedincludes\class-admin-bug-report.php:142
actionadmin_enqueue_scriptsincludes\class-admin-bug-report.php:155
actionadmin_enqueue_scriptsincludes\class-admin-bug-report.php:156
actioninitincludes\class-admin-bug-report.php:158
filterplugin_action_links_admin-bug-report/plugins-stats-dashboard.phpincludes\class-admin-bug-report.php:160
actionadmin_menuincludes\class-admin-bug-report.php:162
actionadmin_footerincludes\class-admin-bug-report.php:164
Maintenance & Trust

Admin Bug Report Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 6, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Admin Bug Report Developer Profile

David Baumwald

9 plugins · 12K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Admin Bug Report

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/admin-bug-report/assets/dist/bugReportCss.min.css/wp-content/plugins/admin-bug-report/assets/dist/settingsCss.min.css/wp-content/plugins/admin-bug-report/assets/dist/bugReportJs.min.js/wp-content/plugins/admin-bug-report/assets/dist/settingsJs.min.js
Script Paths
/wp-content/plugins/admin-bug-report/assets/dist/bugReportJs.min.js/wp-content/plugins/admin-bug-report/assets/dist/settingsJs.min.js
Version Parameters
admin-bug-report/assets/dist/bugReportCss.min.css?ver=admin-bug-report/assets/dist/settingsCss.min.css?ver=admin-bug-report/assets/dist/bugReportJs.min.js?ver=admin-bug-report/assets/dist/settingsJs.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
de-admin-bug-report-settings
Data Attributes
data-report-submit-nonce
JS Globals
DE_ABR
REST Endpoints
/wp-json/admin-bug-report/v1/submit
FAQ

Frequently Asked Questions about Admin Bug Report