
Block Referer Spam Security & Risk Analysis
wordpress.org/plugins/block-referer-spamBlocks referer/referral spam from accessing your site and cleans up your Google Analytics in the process!
Is Block Referer Spam Safe to Use in 2026?
Generally Safe
Score 85/100Block Referer Spam has a strong security track record. Known vulnerabilities have been patched promptly.
The "block-referer-spam" plugin exhibits a mixed security posture. On the positive side, static analysis reveals a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are common sources of vulnerabilities. However, a significant concern lies in the output escaping, with a concerning 38% of outputs not being properly escaped. This could leave the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without adequate sanitization.
The vulnerability history indicates a past XSS vulnerability from 2023, which aligns with the potential risk posed by the unescaped outputs. While there are no currently unpatched CVEs, the presence of past vulnerabilities, especially of the XSS type, coupled with the current code signals of poor output escaping, suggests a recurring area of weakness that needs attention. The lack of any taint flows or critical severity issues in the taint analysis is a positive sign, but it does not negate the risks associated with output escaping.
In conclusion, while the plugin has a well-defined and limited attack surface with good practices around SQL and external requests, the insufficient output escaping presents a tangible risk. The plugin's history of XSS vulnerabilities reinforces the need for developers to prioritize proper sanitization of all outputs to prevent potential exploitation.
Key Concerns
- Insufficient output escaping
- Past XSS vulnerability history
Block Referer Spam Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Block Referer Spam <= 1.1.9.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
Block Referer Spam Code Analysis
Output Escaping
Block Referer Spam Attack Surface
Maintenance & Trust
Block Referer Spam Maintenance & Trust
Maintenance Signals
Community Trust
Block Referer Spam Alternatives
GM Block Bots
gm-block-bots
This blocks semalt.com, buttons-for-website.com and others with a 403 Forbidden message so that they no longer show up in your Google Analytics stats.
Block Referral Spam
wp-block-referral-spam
This plugins blocks maximum Referral Spams. Now no more notice from Google and no more weird report in Google Analytics.
Referer Spam Blocker
referer-spam-blocker
Block/blacklist known (and custom) spam referring domains at the WordPress level with an HTTP 403 Forbidden page.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Block Referer Spam Developer Profile
2 plugins · 620 total installs
How We Detect Block Referer Spam
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-referer-spam/admin/js/dashboard.js/wp-content/plugins/block-referer-spam/admin/css/dashboard.css/wp-content/plugins/block-referer-spam/admin/js/blocked-list.js/wp-content/plugins/block-referer-spam/admin/css/blocked-list.css/wp-content/plugins/block-referer-spam/admin/css/_sidebar.css/wp-content/plugins/block-referer-spam/admin/js/dashboard.js/wp-content/plugins/block-referer-spam/admin/js/blocked-list.jsblock-referer-spam/admin/js/dashboard.js?ver=block-referer-spam/admin/css/dashboard.css?ver=block-referer-spam/admin/js/blocked-list.js?ver=block-referer-spam/admin/css/blocked-list.css?ver=block-referer-spam/admin/css/_sidebar.css?ver=HTML / DOM Fingerprints
ref-block-listref-spam-pro-keyref-spam-pro-activewindow.refSpamBlocker