
ArchivioMD Security & Risk Analysis
wordpress.org/plugins/archiviomdCryptographic content integrity for WordPress — hashing, signing, RFC 3161 timestamps, Rekor transparency log, and DANE corroboration.
Is ArchivioMD Safe to Use in 2026?
Generally Safe
Score 100/100ArchivioMD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The archiviomd plugin v1.19.0 exhibits a generally good security posture with several strong indicators. The high percentage of properly escaped output, comprehensive use of nonce and capability checks, and absence of dangerous functions are commendable. The plugin also shows a positive history with zero known vulnerabilities, suggesting a proactive approach to security by the developers.
However, there are notable areas of concern. The plugin presents a substantial attack surface with 92 entry points, and critically, 11 of these are unprotected, meaning they lack authentication or permission checks. This creates a significant risk, as unauthenticated users could potentially interact with these endpoints in unintended or malicious ways. The presence of 7 taint flows with unsanitized paths, while not classified as critical or high severity, still indicates potential for data manipulation or unintended code execution if user-supplied data is not handled with extreme care throughout the plugin's execution.
In conclusion, while the plugin has demonstrated a strong track record and implements many good security practices, the numerous unprotected entry points and unsanitized data flows represent a tangible risk that needs to be addressed. Developers should prioritize securing all exposed endpoints and rigorously validating all user-supplied input to mitigate these potential vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Taint flows with unsanitized paths
- SQL queries not using prepared statements
ArchivioMD Security Vulnerabilities
ArchivioMD Release Timeline
ArchivioMD Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ArchivioMD Attack Surface
AJAX Handlers 88
REST API Routes 2
Shortcodes 2
WordPress Hooks 68
Maintenance & Trust
ArchivioMD Maintenance & Trust
Maintenance Signals
Community Trust
ArchivioMD Alternatives
ArchivioID
archivioid
OpenPGP signature verification, multi-signer workflows, key lifecycle management, and public proof pages for ArchivioMD.
The GDPR Framework By Data443
gdpr-framework
Easy to use tools to help make your website GDPR-compliant. Fully documented, extendable and developer-friendly. Extensions to enterprise GDPR compli …
Gravity Forms: GDPR Framework Add-On
gdpr-for-gravity-forms
The easiest way to make your Gravity Forms GDPR-compliant. Fully documented, extendable and developer-friendly.
LGPD Framework By Data443
lgpd-framework
Easy to use tools to help you meet LGPD compliance requirements. Fully documented, extendable and developer-friendly. Free, friendly support! Include …
Registration Email Blocker
registration-email-blocker
Block unwanted email domains during user registration. Helps Russian site owners comply with Federal Law 406-FZ requirements for user registration.
ArchivioMD Developer Profile
2 plugins · 0 total installs
How We Detect ArchivioMD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/archiviomd/assets/css/admin.css/wp-content/plugins/archiviomd/assets/js/admin.js/wp-content/plugins/archiviomd/assets/js/admin.jsarchiviomd/assets/css/admin.css?ver=archiviomd/assets/js/admin.js?ver=HTML / DOM Fingerprints
data-file-pathdata-file-namedata-file-sizedata-last-modifieddata-line-numberdata-canary-token-idmdsmData/wp-json/archiviomd/v1/files/wp-json/archiviomd/v1/files/meta/wp-json/archiviomd/v1/sitemap/wp-json/archiviomd/v1/html/wp-json/archiviomd/v1/status/wp-json/archiviomd/v1/changelog/wp-json/archiviomd/v1/canary