
Adrotate Extra Settings Security & Risk Analysis
wordpress.org/plugins/adrotate-extra-settingsUltra light plugin for Wordpress that add new tiny features to AdRotate/AdRotate Pro (not affiliated)
Is Adrotate Extra Settings Safe to Use in 2026?
Generally Safe
Score 85/100Adrotate Extra Settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "adrotate-extra-settings" v1.2.0 plugin exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with unauthenticated access significantly limits the potential attack surface. Furthermore, the code shows no direct vulnerabilities like dangerous functions, raw SQL queries, file operations, or external HTTP requests. The fact that all SQL queries utilize prepared statements is a positive indicator of secure database interaction.
However, a significant concern arises from the low percentage (27%) of properly escaped output. This suggests a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, where unsanitized data could be rendered directly in the browser, potentially leading to code execution or session hijacking. The absence of any recorded vulnerability history is positive, but it does not negate the risks identified in the code analysis. The plugin's security relies heavily on the absence of exploitable entry points, and the unescaped output represents a notable weakness that could be exploited if any data manipulation is possible.
In conclusion, while the plugin avoids common pitfalls like unpatched CVEs and insecure direct database access, the high likelihood of XSS vulnerabilities due to insufficient output escaping is a critical concern. The limited attack surface is a strength, but it's overshadowed by the potential for client-side attacks. A thorough review and remediation of output escaping mechanisms are strongly recommended to improve its overall security.
Key Concerns
- Insufficient output escaping (27% proper)
Adrotate Extra Settings Security Vulnerabilities
Adrotate Extra Settings Code Analysis
Output Escaping
Adrotate Extra Settings Attack Surface
WordPress Hooks 7
Maintenance & Trust
Adrotate Extra Settings Maintenance & Trust
Maintenance Signals
Community Trust
Adrotate Extra Settings Alternatives
AdRotate Switch
adrotate-switch
Looking for a fresh start with AdRotate Banner Manager or AdRotate Professional but you don't want to have to re-do all your ads?
Quads Ads Manager for Google AdSense
quick-adsense-reloaded
Ads & AdSense plugin supporting Media.net, DFP, ads.txt, Web Stories ads, click fraud protection, revenue sharing, and ad blocker detection.
Advanced Ads for WPBakery Page Builder
ads-for-visual-composer
Manage ads in your WPBakery Page Builder interface.
Random Banner
random-banner
Display random image, SWF, or script ads across your WordPress site with this powerful, customizable, and user-friendly Random Banner plugin.
AdPlugg WordPress Ad Plugin
adplugg
Advertising is easy with AdPlugg. The AdPlugg WordPress Ad Plugin and ad server allow you to easily manage, schedule, rotate and track your ads.
Adrotate Extra Settings Developer Profile
4 plugins · 2K total installs
How We Detect Adrotate Extra Settings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.