SpamShieldX Security & Risk Analysis

wordpress.org/plugins/automatic-break-iframes

SpamShieldX is the ultimate solution for protecting your WordPress website from spam and iframe abuse. Our plugin blocks malicious iframes and prevent …

10 active installs v1.2 PHP + WP 5.0+ Updated Apr 28, 2025
anti-spamiframe-blockerspam-protectionwebsite-securitywordpress-firewall
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SpamShieldX Safe to Use in 2026?

Generally Safe

Score 92/100

SpamShieldX has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "automatic-break-iframes" v1.2 plugin presents a generally good security posture based on the provided static analysis and vulnerability history. There are no identified critical or high-severity vulnerabilities, and the plugin boasts zero known CVEs. The absence of dangerous functions, file operations, external HTTP requests, and external HTTP requests further contributes to a strong security foundation. However, there are areas for improvement. The plugin exhibits a concerning lack of output escaping, with only 25% of outputs being properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sanitized before being displayed. Additionally, the single SQL query is not using prepared statements, posing a risk of SQL injection if dynamic data is involved in the query. The plugin also lacks nonce checks and relies on a single capability check for its entry points, which could be insufficient for robust authorization in some scenarios.

Key Concerns

  • Low output escaping percentage
  • SQL query not using prepared statements
  • Lack of nonce checks
Vulnerabilities
None known

SpamShieldX Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SpamShieldX Release Timeline

v1.2Current
v1.1
Code Analysis
Analyzed Mar 17, 2026

SpamShieldX Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
6
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

25% escaped8 total outputs
Attack Surface

SpamShieldX Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_headAutomatic break iframes.php:20
actionadmin_menuAutomatic break iframes.php:28
actionwp_headincludes\ip-blocking.php:17
actionadmin_initincludes\settings.php:32
Maintenance & Trust

SpamShieldX Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 28, 2025
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

SpamShieldX Developer Profile

Alireza Nejati

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SpamShieldX

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wrapbutton-primary
JS Globals
top
FAQ

Frequently Asked Questions about SpamShieldX