
Bearmor Security Security & Risk Analysis
wordpress.org/plugins/bearmor-securityLightweight, powerful WordPress security for small businesses. Malware scanning, login protection, 2FA, hardening - most features FREE.
Is Bearmor Security Safe to Use in 2026?
Generally Safe
Score 100/100Bearmor Security has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bearmor-security plugin v0.9.16 exhibits a generally good security posture with a high percentage of properly escaped output and a significant portion of SQL queries using prepared statements. The absence of known CVEs and a clean vulnerability history are positive indicators. However, the static analysis reveals two AJAX handlers that lack authentication checks, representing a direct attack vector. Furthermore, the taint analysis identifies two flows with unsanitized paths, both categorized as high severity. These findings suggest potential vulnerabilities that could allow for unauthorized actions or data manipulation if exploited. While the plugin demonstrates strengths in secure coding practices, the identified unprotected entry points and high-severity taint flows warrant attention and mitigation.
Key Concerns
- AJAX handlers without auth checks
- Taint flows with unsanitized paths (High severity)
Bearmor Security Security Vulnerabilities
Bearmor Security Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Bearmor Security Attack Surface
AJAX Handlers 13
WordPress Hooks 71
Scheduled Events 15
Maintenance & Trust
Bearmor Security Maintenance & Trust
Maintenance Signals
Community Trust
Bearmor Security Alternatives
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Defender Security – Malware Scanner, Login Security & Firewall
defender-security
WordPress security plugin with malware scanner, IP blocking, audit logs, antivirus scans, firewall, 2FA, brute force login security, and more.
BulletProof Security
bulletproof-security
WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup, Anti-Spam...
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
limit-login-attempts-reloaded
Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
Security Optimizer – The All-In-One Protection Plugin
sg-security
Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to use and easy to set up.
Bearmor Security Developer Profile
1 plugin · 50 total installs
How We Detect Bearmor Security
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bearmor-security/assets/css/bearmor.css/wp-content/plugins/bearmor-security/assets/js/bearmor-admin.js/wp-content/plugins/bearmor-security/assets/js/bearmor-settings.js/wp-content/plugins/bearmor-security/assets/js/bearmor-admin.js/wp-content/plugins/bearmor-security/assets/js/bearmor-settings.jsbearmor-security/assets/css/bearmor.css?ver=bearmor-security/assets/js/bearmor-admin.js?ver=bearmor-security/assets/js/bearmor-settings.js?ver=HTML / DOM Fingerprints
bearmor-settings-pagebearmor-section-titlebearmor-tablebearmor-log-entrybearmor-blocked-ip-status<!-- Bearmor Security Settings --><!-- Bearmor Admin Notice --><!-- Bearmor Log Entry --><!-- Bearmor Blocked IP Item -->data-bearmor-setting-groupdata-bearmor-ip-iddata-bearmor-log-idbearmor_admin_paramsbearmor_settings_paramsbearmor_ajax_object/wp-json/bearmor/v1/settings/wp-json/bearmor/v1/logs/wp-json/bearmor/v1/ip-block[bearmor_security_widget][bearmor_status_display]