Antispam Bee Security & Risk Analysis

wordpress.org/plugins/antispam-bee

Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.

700K active installs v2.11.8 PHP 5.2+ WP 4.6+ Updated Jul 22, 2025
anti-spamantispamcommentsspam-filterspam-protection
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 27, 2023
Safety Verdict

Is Antispam Bee Safe to Use in 2026?

Generally Safe

Score 100/100

Antispam Bee has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 27, 2023Updated 8mo ago
Risk Assessment

The Anti-Spam Bee plugin, version 2.11.8, exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good development practices by largely utilizing prepared statements for SQL queries and properly escaping output, with an impressive 98% of outputs being escaped. The absence of critical or high-severity taint flows and dangerous functions is also a positive indicator. However, the presence of two flows with unsanitized paths, even though not classified as critical or high, warrants attention as it suggests potential indirect risks if these paths are ever exposed to malicious input.

The vulnerability history reveals one medium-severity CVE, last patched in late 2023. While this indicates a past weakness related to reliance on untrusted inputs in a security decision, the fact that it's currently patched and no critical or high vulnerabilities are present is reassuring. The plugin has a very small attack surface with no unprotected entry points identified in the static analysis, which is a significant strength. The single cron event and file operation, along with limited external HTTP requests, are not inherently risky given the context of a security plugin, but would require deeper analysis in a real-world scenario.

In conclusion, Anti-Spam Bee version 2.11.8 appears to be a relatively secure plugin. Its strengths lie in its limited attack surface, robust use of prepared statements and output escaping, and a clean vulnerability history of recently patched medium-severity issues. The primary area for concern, albeit minor based on the provided data, is the presence of unsanitized paths in taint flows, which could represent a subtle risk if not carefully managed.

Key Concerns

  • Flows with unsanitized paths found
  • Past medium severity CVE
Vulnerabilities
1

Antispam Bee Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-41134medium · 5.3Reliance on Untrusted Inputs in a Security Decision

Antispam Bee <= 2.11.3 - IP Address Spoofing via get_client_ip

Nov 27, 2023 Patched in 2.11.4 (57d)
Code Analysis
Analyzed Mar 16, 2026

Antispam Bee Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
8 prepared
Unescaped Output
1
55 escaped
Nonce Checks
1
Capability Checks
4
File Operations
1
External Requests
3
Bundled Libraries
0

SQL Query Safety

73% prepared11 total queries

Output Escaping

98% escaped56 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
filter_columns (inc\columns.class.php:101)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Antispam Bee Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 32
actionupgrader_process_completeantispam_bee.php:98
actionupgrader_overwrote_packageantispam_bee.php:108
actionunspam_commentantispam_bee.php:118
actioncomment_unapproved_to_spamantispam_bee.php:126
actioncomment_approved_to_spamantispam_bee.php:134
actioninitantispam_bee.php:154
actionantispam_bee_daily_cronjobantispam_bee.php:163
actionadmin_menuantispam_bee.php:172
filterdashboard_glance_itemsantispam_bee.php:181
actionwp_dashboard_setupantispam_bee.php:188
filterplugin_row_metaantispam_bee.php:197
actionadmin_initantispam_bee.php:215
actionadmin_initantispam_bee.php:222
actionadmin_post_ab_save_changesantispam_bee.php:233
filtermanage_edit-comments_columnsantispam_bee.php:247
filtermanage_comments_custom_columnantispam_bee.php:254
filteradmin_print_styles-edit-comments.phpantispam_bee.php:263
filtermanage_edit-comments_sortable_columnsantispam_bee.php:271
actionpre_get_commentsantispam_bee.php:278
actionrestrict_manage_commentsantispam_bee.php:285
actionpre_get_commentsantispam_bee.php:292
actionwpantispam_bee.php:302
actiontemplate_redirectantispam_bee.php:311
filtercomment_form_field_commentantispam_bee.php:319
actioninitantispam_bee.php:329
filterpreprocess_commentantispam_bee.php:336
actionantispam_bee_countantispam_bee.php:344
actionadmin_headantispam_bee.php:791
filterpre_comment_approvedantispam_bee.php:2334
actioncomment_postantispam_bee.php:2343
actioncomment_postantispam_bee.php:2353
actionplugins_loadedantispam_bee.php:2977

Scheduled Events 1

antispam_bee_daily_cronjob
Maintenance & Trust

Antispam Bee Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 22, 2025
PHP min version5.2
Downloads11.0M

Community Trust

Rating96/100
Number of ratings225
Active installs700K
Developer Profile

Antispam Bee Developer Profile

pluginkollektiv

8 plugins · 846K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
1972 days
View full developer profile
Detection Fingerprints

How We Detect Antispam Bee

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/antispam-bee/css/antispam-bee.css/wp-content/plugins/antispam-bee/css/antispam-bee-dashboard.css/wp-content/plugins/antispam-bee/js/antispam-bee.js
Script Paths
/wp-content/plugins/antispam-bee/js/antispam-bee.js
Version Parameters
antispam-bee/css/antispam-bee.css?ver=antispam-bee/css/antispam-bee-dashboard.css?ver=antispam-bee/js/antispam-bee.js?ver=

HTML / DOM Fingerprints

CSS Classes
antispam-bee-spam-countantispam-bee-dashboard-chart
HTML Comments
<!-- Generated by Antispam Bee --><!-- Antispam Bee: Your comment is being held for review. --><!-- Antispam Bee: This comment is spam. -->
Data Attributes
data-antispam-bee-id
JS Globals
antispamBeeAntispamBeeSettings
FAQ

Frequently Asked Questions about Antispam Bee