Ambiscale Activity Manager Security & Risk Analysis

wordpress.org/plugins/ambiscale-activity-manager

Monitor your website by logging all activities - from user behavior to system-level changes - giving you complete visibility directly from dashboard.

70 active installs v1.1.2 PHP 7.4+ WP 6.2+ Updated Feb 23, 2026
activityhistorylogsmonitoringsecurity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ambiscale Activity Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Ambiscale Activity Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The ambiscale-activity-manager plugin version 1.1.2 demonstrates a generally positive security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, all SQL queries utilize prepared statements, which is a strong defense against SQL injection. The presence of nonce and capability checks indicates an effort to enforce proper authorization and prevent cross-site request forgery.

However, a significant concern arises from the low percentage of properly escaped output (22%). This suggests a substantial risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data may be rendered without proper sanitization, allowing attackers to inject malicious scripts. The limited taint analysis, while showing no immediate critical or high severity flows, does not fully mitigate this output escaping concern. The plugin's clean vulnerability history is a positive sign, implying responsible development and maintenance, but it does not negate the identified risks within the current code.

In conclusion, while the plugin has implemented several good security practices, particularly regarding its attack surface and SQL query handling, the prevalent lack of output escaping represents a notable weakness. This area requires immediate attention to reduce the risk of XSS attacks. The plugin's history of no known vulnerabilities is encouraging but should not lead to complacency regarding the identified code-level concerns.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Ambiscale Activity Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ambiscale Activity Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
15 prepared
Unescaped Output
83
24 escaped
Nonce Checks
6
Capability Checks
4
File Operations
8
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared15 total queries

Output Escaping

22% escaped107 total outputs
Attack Surface

Ambiscale Activity Manager Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Ambiscale Activity Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs70
Developer Profile

Ambiscale Activity Manager Developer Profile

Ambiscale

2 plugins · 70 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ambiscale Activity Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ambiscale-activity-manager/dist/css/main.css/wp-content/plugins/ambiscale-activity-manager/dist/js/main.js
Script Paths
/wp-content/plugins/ambiscale-activity-manager/dist/js/main.js
Version Parameters
ambiscale-activity-manager/dist/css/main.css?ver=ambiscale-activity-manager/dist/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
ambiscale-activity-manageraam-dashboardaam-settingsaam-logsaam-debug-logsaam-health-clear-databaseaam-health-clear-filesaam-health-clear-debug+3 more
HTML Comments
<!-- Begin Ambiscale Activity Manager Admin --><!-- End Ambiscale Activity Manager Admin --><!-- Begin Ambiscale Activity Manager Dashboard Page --><!-- End Ambiscale Activity Manager Dashboard Page -->+6 more
Data Attributes
data-nonce="ambiscale-activity-manager_ajax_nonce"data-clear-database-noncedata-clear-files-noncedata-clear-debug-nonce
JS Globals
aamVars
FAQ

Frequently Asked Questions about Ambiscale Activity Manager