
AMP & Non-AMP Auto Ads Security & Risk Analysis
wordpress.org/plugins/amp-non-amp-auto-adsAMP non-AMP Auto Ads, is simple but effective plugins to allow you place automated ads on your AMP WordPress site or Regular WordPress site( Site not …
Is AMP & Non-AMP Auto Ads Safe to Use in 2026?
Generally Safe
Score 85/100AMP & Non-AMP Auto Ads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "amp-non-amp-auto-ads" plugin v1.0.0 demonstrates a strong adherence to several security best practices, particularly in its minimal attack surface and the absence of critical code signals like dangerous functions or file operations. The fact that all SQL queries utilize prepared statements is a significant positive, mitigating a common vulnerability vector. Furthermore, the plugin's history shows no known CVEs, suggesting a relatively stable and well-maintained codebase, at least concerning publicly disclosed vulnerabilities.
However, the static analysis reveals a significant concern regarding output escaping, with only 7% of outputs being properly escaped. This widespread lack of proper output escaping presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied or dynamic data that is not correctly escaped before being displayed to users can be manipulated to inject malicious scripts. The absence of nonce checks and capability checks, while not directly flagged as issues due to the lack of exposed entry points in this specific version, indicates a potential weakness if the plugin's attack surface were to expand or change in future versions.
In conclusion, while the plugin's low attack surface and SQL practices are commendable, the severe deficiency in output escaping is a critical flaw that significantly elevates the risk profile. The lack of past vulnerabilities is encouraging, but it does not negate the present danger posed by unescaped output. Users should be aware of the potential for XSS attacks and consider this plugin's security posture carefully.
Key Concerns
- Low output escaping percentage
- Lack of capability checks
- Lack of nonce checks
AMP & Non-AMP Auto Ads Security Vulnerabilities
AMP & Non-AMP Auto Ads Code Analysis
Output Escaping
AMP & Non-AMP Auto Ads Attack Surface
WordPress Hooks 11
Maintenance & Trust
AMP & Non-AMP Auto Ads Maintenance & Trust
Maintenance Signals
Community Trust
AMP & Non-AMP Auto Ads Alternatives
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
Tracking Code Manager
tracking-code-manager
A plugin to manage ALL of your tracking code and conversion pixels. Compatible with Facebook Ads, Google Adwords, WooCommerce, Easy Digital Downloads, …
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Quick Adsense
quick-adsense
Quick Adsense offers a quicker & flexible way to insert Google Adsense or any Ads code into a blog post.
Conversios: Google Analytics (GA4), Google Ads, Conversion and Analytics Tracking for Multi-Channels
enhanced-e-commerce-for-woocommerce-store
Track GA4 Analytics, Google Ads, Microsoft Ads, & Conversion with server-side tracking (CAPI) & product feed to improve ROAS, reports for WooCommerce.
AMP & Non-AMP Auto Ads Developer Profile
3 plugins · 30 total installs
How We Detect AMP & Non-AMP Auto Ads
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/amp-non-amp-auto-ads/css/ampnonampads-admin.css/wp-content/plugins/amp-non-amp-auto-ads/js/ampnonampads-admin.js/wp-content/plugins/amp-non-amp-auto-ads/js/ampnonampads-admin.jsampnonampads-admin.css?ver=ampnonampads-admin.js?ver=HTML / DOM Fingerprints
<!-- Piclaunch Code -->