All in one WP Content Protector Security & Risk Analysis

wordpress.org/plugins/all-in-one-wp-content-security

Plugin: Content Security Configurator. Blocks keyboard events, image dragging, and disables browser console & inspect element for frontend visitors.

100 active installs v2.0 PHP 5.6+ WP 4.5+ Updated Mar 7, 2025
content-protectioncopy-protectionelement-selection-protectionimage-protectionright-click-protection
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is All in one WP Content Protector Safe to Use in 2026?

Generally Safe

Score 92/100

All in one WP Content Protector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "all-in-one-wp-content-security" v2.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, coupled with a clean vulnerability history, suggests a commitment to security and effective patching if issues arise. The static analysis further reinforces this, showing zero identified attack vectors like unprotected AJAX handlers, REST API routes, or shortcodes. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage of properly escaped output. The low number of file operations and zero external HTTP requests are also positive indicators.

However, there are a few areas that, while not indicating immediate critical risks based on the current data, warrant attention for further hardening. The plugin has zero capability checks, which is a concern. While the current attack surface is minimal and appears to be protected by WordPress's core authentication, relying solely on this without explicit capability checks for any internal logic that might be added in future updates could pose a risk. The presence of file operations, even if not flagged as malicious, means there's a potential for misuse if not carefully implemented and validated. The low number of nonce checks (3) for the operations it does perform also leaves room for improvement in terms of granular protection against replay attacks.

In conclusion, the plugin is currently in a very good security state, with no known vulnerabilities or immediately exploitable flaws identified. Its strengths lie in its minimal attack surface and good SQL and output sanitization practices. The main areas for potential improvement revolve around strengthening internal authorization with capability checks and potentially increasing nonce implementation for enhanced protection against various attack vectors.

Key Concerns

  • No capability checks found
  • Low number of nonce checks
Vulnerabilities
None known

All in one WP Content Protector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

All in one WP Content Protector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
75 escaped
Nonce Checks
3
Capability Checks
0
File Operations
6
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped77 total outputs
Attack Surface

All in one WP Content Protector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptsincludes\class-all-in-one-wp-content-security-core.php:42
actionadmin_menuincludes\class-all-in-one-wp-content-security-core.php:43
actioninitincludes\class-all-in-one-wp-content-security-core.php:44
filterplugin_action_links_all-in-one-wp-content-security/all-in-one-wp-content-security.phpincludes\class-all-in-one-wp-content-security-core.php:45
actionwp_headincludes\class-all-in-one-wp-content-security-core.php:52
Maintenance & Trust

All in one WP Content Protector Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 7, 2025
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

All in one WP Content Protector Developer Profile

Mahesh Thorat

4 plugins · 130 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All in one WP Content Protector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/all-in-one-wp-content-security/assets/styles/standalone.css
Version Parameters
all-in-one-wp-content-security/assets/styles/standalone.css?ver=

HTML / DOM Fingerprints

CSS Classes
dashicons-admin-toolsdashicons-editor-helpdashicons-money-alt
FAQ

Frequently Asked Questions about All in one WP Content Protector