Advanced WPMU Plugin Manager Security & Risk Analysis

wordpress.org/plugins/advanced-wpmu-plugin-manager

A plugin which Enable Network admin/Super admin to manage the Plugins for Individual Blog in the Multi site network.

10 active installs v1.0 PHP + WP 3.3+ Updated Aug 31, 2012
wpmu-plugin-managment
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Advanced WPMU Plugin Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced WPMU Plugin Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The 'advanced-wpmu-plugin-manager' v1.0 plugin exhibits a concerning security posture despite its lack of recorded vulnerabilities. The static analysis reveals a significant attack surface with 3 AJAX handlers, all of which lack authentication checks. This presents a clear risk of unauthorized actions being performed if an attacker can trigger these handlers. Furthermore, the analysis indicates a critical flaw in output sanitization, with 0% of outputs being properly escaped. This means that user-supplied data could potentially be injected into the output without sanitization, leading to cross-site scripting (XSS) vulnerabilities. While the plugin uses prepared statements for its SQL queries and has no recorded CVEs, the critical findings in the AJAX endpoints and output escaping overshadow these positive aspects.

Key Concerns

  • AJAX handlers without authentication checks
  • No output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Advanced WPMU Plugin Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Advanced WPMU Plugin Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
9
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped9 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
awpm_load_site_plugin (init.php:179)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Advanced WPMU Plugin Manager Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_awpm_load_site_plugininit.php:177
authwp_ajax_awpm_activate_plugininit.php:208
authwp_ajax_awpm_deactivate_plugininit.php:222
WordPress Hooks 1
actionnetwork_admin_menuinit.php:15
Maintenance & Trust

Advanced WPMU Plugin Manager Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedAug 31, 2012
PHP min version
Downloads4K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Alternatives

Advanced WPMU Plugin Manager Alternatives

No alternatives data available yet.

Developer Profile

Advanced WPMU Plugin Manager Developer Profile

anthakkar08

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Advanced WPMU Plugin Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/advanced-wpmu-plugin-manager/img/facebook.png/wp-content/plugins/advanced-wpmu-plugin-manager/img/twitter.png/wp-content/plugins/advanced-wpmu-plugin-manager/img/wordpress.png

HTML / DOM Fingerprints

CSS Classes
col1col2socialloading
Data Attributes
plugindata-plugin
JS Globals
awpm_load_site_pluginawpm_activate_pluginawpm_deactivate_plugin
FAQ

Frequently Asked Questions about Advanced WPMU Plugin Manager