ads.txt Guru Connect Security & Risk Analysis

wordpress.org/plugins/adstxt-guru-connect

ads.txt Guru is a revolutionary tool to eliminate the burden of maintaining website ads.txt files!

80 active installs v1.1.2 PHP 5.0+ WP 2.8+ Updated Aug 15, 2025
ads-txtadstxtadvertisingmanagervalidation
99
A · Safe
CVEs total1
Unpatched0
Last CVEAug 20, 2025
Safety Verdict

Is ads.txt Guru Connect Safe to Use in 2026?

Generally Safe

Score 99/100

ads.txt Guru Connect has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 20, 2025Updated 7mo ago
Risk Assessment

The 'adstxt-guru-connect' v1.1.2 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks. There are no identified taint flows of critical or high severity, and the attack surface appears to be minimal with no apparent unprotected entry points. This suggests a generally cautious approach to handling user-supplied data and securing critical operations.

However, significant concerns arise from the use of the `unserialize` function, which is inherently dangerous if not handled with extreme care, as it can lead to Remote Code Execution vulnerabilities if untrusted data is serialized and then unserialized. Furthermore, the output escaping is alarmingly low at only 14%, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin's history of a known CVE, although currently patched, suggests a past vulnerability that might have been related to Cross-Site Request Forgery (CSRF), and the medium severity of this historical vulnerability warrants attention.

In conclusion, while the plugin has strengths in its SQL handling and nonce checks, the presence of `unserialize` and critically low output escaping represent substantial security weaknesses. The historical CVE, even if patched, serves as a reminder of potential past flaws. The overall risk is moderate to high due to the potential for severe vulnerabilities like RCE and XSS.

Key Concerns

  • Dangerous function: unserialize used
  • Low output escaping (14%)
  • Medium severity vulnerability in history
Vulnerabilities
1

ads.txt Guru Connect Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49381medium · 4.3Cross-Site Request Forgery (CSRF)

ads.txt Guru Connect <= 1.1.1 - Cross-Site Request Forgery

Aug 20, 2025 Patched in 1.1.2 (7d)
Code Analysis
Analyzed Mar 16, 2026

ads.txt Guru Connect Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
6
1 escaped
Nonce Checks
3
Capability Checks
1
File Operations
7
External Requests
3
Bundled Libraries
0

Dangerous Functions Found

unserialize$option = unserialize(base64_decode($option));adstxt_guru_connect.php:673

Output Escaping

14% escaped7 total outputs
Attack Surface

ads.txt Guru Connect Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitadstxt_guru_connect.php:39
actioninitadstxt_guru_connect.php:45
actionadmin_menuadstxt_guru_connect.php:59
Maintenance & Trust

ads.txt Guru Connect Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 15, 2025
PHP min version5.0
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

ads.txt Guru Connect Developer Profile

ads.txt Guru

1 plugin · 80 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect ads.txt Guru Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/adstxt-guru-connect/assets/css/adstxt-guru-connect.css
Version Parameters
adstxt-guru-connect/assets/css/adstxt-guru-connect.css?ver=

HTML / DOM Fingerprints

CSS Classes
adstxt-guru-connect-wrap
HTML Comments
<!-- ATG-CUSTOM -->
Data Attributes
data-atg-connect-keydata-atg-connect-secret
JS Globals
ATG_CONNECT_OBJ
FAQ

Frequently Asked Questions about ads.txt Guru Connect