Blacklist keys manager Security & Risk Analysis

wordpress.org/plugins/blacklist-keys-manager

The increase in efficiency of management of a comment blacklist is attained, and a spam comment is blocked.

10 active installs v1.2.0 PHP + WP 3.5.0+ Updated May 22, 2015
blacklistcommentmoderationspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Blacklist keys manager Safe to Use in 2026?

Generally Safe

Score 85/100

Blacklist keys manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "blacklist-keys-manager" v1.2.0 plugin exhibits a generally good security posture based on the provided static analysis. There are no identified critical or high-severity vulnerabilities from taint analysis, and the plugin demonstrates sound practices such as using prepared statements for all SQL queries and performing nonce checks on its entry points. The absence of known CVEs and a clean vulnerability history further contribute to this positive assessment.

However, there are areas that warrant attention. The plugin has a moderate output escaping rate (45%), which indicates a potential risk for cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being rendered in the browser. While the attack surface is small and appears to be protected by authentication checks, the presence of file operations without further context could introduce risks if not handled with extreme care. The limited number of capability checks is also a potential concern, as it might not sufficiently restrict access to sensitive functionalities.

In conclusion, "blacklist-keys-manager" v1.2.0 is likely safe for use given its current state, but the moderate output escaping and the file operation warrant careful review. The plugin's lack of past vulnerabilities is a strong indicator of responsible development. Focusing on improving output escaping and thoroughly auditing the file operation functionality would further strengthen its security.

Key Concerns

  • Moderate output escaping (45%)
  • Presence of file operations
  • Limited capability checks
Vulnerabilities
None known

Blacklist keys manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Blacklist keys manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
14 escaped
Nonce Checks
3
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

45% escaped31 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
properties (blacklist-keys-manager.php:396)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Blacklist keys manager Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_test_exblacklistblacklist-keys-manager.php:42
authwp_ajax_upload_white_list_file_for_commentblacklist-keys-manager.php:44
WordPress Hooks 7
actionadmin_initblacklist-keys-manager.php:27
actionadmin_menublacklist-keys-manager.php:28
actionadmin_headblacklist-keys-manager.php:30
actionspammed_commentblacklist-keys-manager.php:36
filterpre_comment_approvedblacklist-keys-manager.php:38
filterpre_comment_approvedblacklist-keys-manager.php:41
filtercomments_clausesblacklist-keys-manager.php:310
Maintenance & Trust

Blacklist keys manager Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedMay 22, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Blacklist keys manager Developer Profile

tmatsuur

8 plugins · 21K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
1904 days
View full developer profile
Detection Fingerprints

How We Detect Blacklist keys manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/blacklist-keys-manager/js/script.js/wp-content/plugins/blacklist-keys-manager/css/style.css
Script Paths
/wp-content/plugins/blacklist-keys-manager/js/script.js
Version Parameters
blacklist-keys-manager/js/script.js?ver=blacklist-keys-manager/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
drag-frameform-tableedit-framekey-count
HTML Comments
<!-- clearfix --><!-- Hides from IE-mac \--><!-- End hide from IE-mac -->
Data Attributes
data-key-id
JS Globals
blacklist_keys_manager_params
FAQ

Frequently Asked Questions about Blacklist keys manager