Anti Browser DDoS Protection Security & Risk Analysis

wordpress.org/plugins/anti-browser-ddos-protection

Protects WordPress from DDoS with rate limiting, bot detection, blocking, Cloudflare support, logs, charts, and bot list export/import.

60 active installs v2.26 PHP 8.3+ WP 5.0+ Updated Sep 19, 2025
bot-blockingddos-protectionip-blockingrate-limitingsecurity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Anti Browser DDoS Protection Safe to Use in 2026?

Generally Safe

Score 100/100

Anti Browser DDoS Protection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "anti-browser-ddos-protection" plugin v2.26 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the strict adherence to prepared statements for SQL queries are significant strengths. Furthermore, the analysis indicates a good implementation of WordPress security best practices, with a reasonable percentage of output escaping and a healthy number of nonce and capability checks relative to the entry points. The lack of critical or high-severity taint flows is also reassuring.

However, there are minor areas for improvement. While the total number of entry points is low, and all are protected by authentication checks, a higher percentage of properly escaped outputs would further strengthen its defense against potential cross-site scripting (XSS) vulnerabilities. The presence of file operations, while not inherently dangerous, warrants attention to ensure these operations are performed securely and do not introduce any unintended risks. The plugin's clean vulnerability history is a positive indicator of its development quality, suggesting a focus on security by the maintainers.

In conclusion, "anti-browser-ddos-protection" v2.26 appears to be a securely developed plugin with a commendable track record. The key strengths lie in its secure handling of database queries and its robust use of authentication and capability checks. The minor weakness lies in the slightly lower-than-ideal output escaping percentage, which, while not critical, could be improved to achieve a truly exemplary security profile.

Key Concerns

  • Output escaping is not fully implemented (73%)
Vulnerabilities
None known

Anti Browser DDoS Protection Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Anti Browser DDoS Protection Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
46
124 escaped
Nonce Checks
7
Capability Checks
10
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

73% escaped170 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
abdp_settings_page (anti-browser-ddos-protection.php:324)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Anti Browser DDoS Protection Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 1

authwp_ajax_abdp_refresh_nonceanti-browser-ddos-protection.php:250

REST API Routes 3

GET/wp-json/abdp/v1/blocked-ipsanti-browser-ddos-protection.php:661
GET/wp-json/abdp/v1/banned-ipsanti-browser-ddos-protection.php:669
GET/wp-json/abdp/v1/high-traffic-botsanti-browser-ddos-protection.php:677
WordPress Hooks 11
actionadmin_menuanti-browser-ddos-protection.php:159
actionadmin_noticesanti-browser-ddos-protection.php:175
actioninitanti-browser-ddos-protection.php:240
actionabdp_cleanup_logs_eventanti-browser-ddos-protection.php:247
actionadmin_enqueue_scriptsanti-browser-ddos-protection.php:259
actionadmin_post_abdp_export_excluded_botsanti-browser-ddos-protection.php:284
actionadmin_post_abdp_export_bot_ip_rangesanti-browser-ddos-protection.php:297
actionadmin_post_abdp_export_blocked_botsanti-browser-ddos-protection.php:310
actionrest_api_initanti-browser-ddos-protection.php:659
actionadmin_initanti-browser-ddos-protection.php:724
actionwp_loadedanti-browser-ddos-protection.php:814

Scheduled Events 1

abdp_cleanup_logs_event
Maintenance & Trust

Anti Browser DDoS Protection Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 19, 2025
PHP min version8.3
Downloads422

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Anti Browser DDoS Protection Developer Profile

sourcecode347

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Anti Browser DDoS Protection

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anti-browser-ddos-protection/js/abdp-script.js/wp-content/plugins/anti-browser-ddos-protection/css/abdp-style.css
Script Paths
/wp-content/plugins/anti-browser-ddos-protection/js/abdp-script.js
Version Parameters
anti-browser-ddos-protection/js/abdp-script.js?ver=anti-browser-ddos-protection/css/abdp-style.css?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Anti Browser DDoS Protection Settings --><!-- Anti Browser DDoS Settings --><!-- ABDP Admin Notice -->
Data Attributes
data-abdp-admin-notice
JS Globals
var abdp_settings = window.abdp_settings =
FAQ

Frequently Asked Questions about Anti Browser DDoS Protection