Anti-spam Reloaded Security & Risk Analysis

wordpress.org/plugins/anti-spam-reloaded

No spam in comments. No captcha.

2K active installs v6.5 PHP 5.6+ WP 3.3+ Updated May 3, 2024
commentcomment-spamcommentsspamspammer
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Anti-spam Reloaded Safe to Use in 2026?

Generally Safe

Score 92/100

Anti-spam Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The anti-spam-reloaded v6.5 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a history of zero recorded vulnerabilities, combined with no critical or high-severity issues flagged in taint analysis, suggests a generally well-maintained and secure codebase. The plugin also demonstrates good practices by having a zero attack surface for AJAX handlers and REST API routes without authentication checks, no dangerous functions, and all SQL queries using prepared statements. A positive indicator is the presence of a nonce check, though the lack of capability checks is a minor concern that could be addressed.

However, the static analysis does highlight a potential weakness in output escaping, with only 36% of outputs being properly escaped. This could leave the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed. While no specific XSS issues were identified in the taint analysis, this percentage is a significant area for improvement. The plugin's limited attack surface and clean vulnerability history are strong positives, but the output escaping issue represents the primary area requiring attention to further strengthen its security.

Key Concerns

  • Low percentage of properly escaped output
  • Missing capability checks on entry points
Vulnerabilities
None known

Anti-spam Reloaded Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Anti-spam Reloaded Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

36% escaped14 total outputs
Attack Surface

Anti-spam Reloaded Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_noticesanti-spam-info.php:38
filterscreen_layout_columnsanti-spam-info.php:77
actionadmin_headanti-spam-info.php:79
actionadmin_initanti-spam-info.php:94
actionadmin_menuanti-spam-settings.php:15
actionadmin_initanti-spam-settings.php:26
actionadmin_initanti-spam-settings.php:32
actionplugins_loadedanti-spam.php:26
actionwp_enqueue_scriptsanti-spam.php:40
actioncomment_formanti-spam.php:63
filterpreprocess_commentanti-spam.php:92
filterplugin_row_metaanti-spam.php:105
Maintenance & Trust

Anti-spam Reloaded Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 3, 2024
PHP min version5.6
Downloads15K

Community Trust

Rating100/100
Number of ratings14
Active installs2K
Developer Profile

Anti-spam Reloaded Developer Profile

kudlav

1 plugin · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Anti-spam Reloaded

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anti-spam-reloaded/js/anti-spam.min.js
Script Paths
/wp-content/plugins/anti-spam-reloaded/js/anti-spam.min.js
Version Parameters
anti-spam-reloaded/js/anti-spam.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
antispamrel-groupantispamrel-control-qantispamrel-control-aantispamrel-control-e
HTML Comments
<!-- Anti-spam Reloaded plugin wordpress.org/plugins/anti-spam-reloaded/ --><!-- empty field (hidden with css): trap for spammers because many bots will try to put email or url here -->
Data Attributes
name="antspmrl-q"class="antispamrel-control-q"name="antspmrl-a"class="antispamrel-control-a"name="antspmrl-e-email-url-website"class="antispamrel-control-e"
JS Globals
antspmrl_advsettantispamrel_screen_options_groupantspmrl_advoptsantispamrel_info_nonceantispamrel_info_visibility
FAQ

Frequently Asked Questions about Anti-spam Reloaded