Bulk Manager Security & Risk Analysis

wordpress.org/plugins/bulk-manager

An easier way to update/delete your pages/posts content, excerpt, categories, tags, taxonomies, author and media at once.

0 active installs v1.0.0 PHP + WP 5.0+ Updated Feb 8, 2024
bulkbulk-cleanbulk-deletebulk-updateposts-update
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bulk Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Bulk Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "bulk-manager" v1.0.0 plugin exhibits a generally strong security posture, with several positive indicators. All identified entry points (10 AJAX handlers) appear to have authentication checks, which is a critical security measure. Furthermore, the plugin demonstrates excellent coding practices by using prepared statements for all SQL queries and properly escaping all outputs, with no file operations or external HTTP requests observed. The presence of 13 nonce checks also suggests a commitment to preventing cross-site request forgery.

However, a significant concern arises from the taint analysis, which identified 5 flows with unsanitized paths, all categorized as high severity. This indicates potential vulnerabilities where user-supplied data might not be adequately validated or sanitized before being used in sensitive operations, even though no direct SQL injection or output escaping issues were found. The complete absence of capability checks is another notable weakness, as it means that authenticated users might be able to perform actions they shouldn't, potentially leading to privilege escalation or unintended data manipulation. The plugin's vulnerability history shows no recorded CVEs, which is positive, but the presence of high-severity taint flows necessitates caution until these are fully addressed.

In conclusion, while the plugin has implemented some crucial security best practices, the high-severity taint flows and lack of capability checks represent significant risks. The absence of historical vulnerabilities is a good sign, but the current taint analysis findings should be prioritized for investigation and remediation to ensure a robust security profile.

Key Concerns

  • High severity unsanitized taint flows
  • Missing capability checks on entry points
Vulnerabilities
None known

Bulk Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Bulk Manager Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Bulk Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
257 escaped
Nonce Checks
13
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped258 total outputs
Data Flows · Security
5 unsanitized

Data Flow Analysis

7 flows5 with unsanitized paths
save_fields (includes\Admin\Settings.php:713)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bulk Manager Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 10

authwp_ajax_update_post_dataincludes\Ajax.php:15
authwp_ajax_load_taxonomy_termsincludes\Ajax.php:16
authwp_ajax_load_posts_by_termsincludes\Ajax.php:17
authwp_ajax_load_posts_by_typeincludes\Ajax.php:18
authwp_ajax_load_taxonomies_by_post_typeincludes\Ajax.php:19
authwp_ajax_get_post_dataincludes\Ajax.php:20
authwp_ajax_get_registered_taxonomiesincludes\Ajax.php:21
authwp_ajax_get_taxonomies_termincludes\Ajax.php:22
authwp_ajax_update_taxonomyincludes\Ajax.php:23
authwp_ajax_taxonomy_terms_updateincludes\Ajax.php:24
WordPress Hooks 8
actionplugins_loadedbulk-manager.php:47
actionplugins_loadedbulk-manager.php:48
actionadmin_menuincludes\Admin\Menu.php:15
actionwp_loadedincludes\Admin\Menu.php:16
filteradmin_settings_tabsincludes\Admin\Settings\Page.php:20
actionwp_enqueue_scriptsincludes\Assets.php:15
actionadmin_enqueue_scriptsincludes\Assets.php:16
actioninitincludes\Generator.php:23
Maintenance & Trust

Bulk Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 8, 2024
PHP min version
Downloads822

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Bulk Manager Developer Profile

redq

7 plugins · 320 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bulk Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bulk-manager/assets/js/jquery.tipTip.min.js/wp-content/plugins/bulk-manager/assets/js/admin.js/wp-content/plugins/bulk-manager/dist/bulk-global.css/wp-content/plugins/bulk-manager/dist/bulk-tailwind.css
Script Paths
/wp-content/plugins/bulk-manager/assets/js/jquery.tipTip.min.js/wp-content/plugins/bulk-manager/assets/js/admin.js
Version Parameters
bulk-manager/assets/js/jquery.tipTip.min.js?ver=bulk-manager/assets/js/admin.js?ver=bulk-manager/dist/bulk-global.css?ver=bulk-manager/dist/bulk-tailwind.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-bulk-manager-editor-templatedata-bulk-manager-posts-templatedata-bulk-manager-categories-templatedata-bulk-manager-tags-template
JS Globals
BULK_MANAGER_ADMIN
REST Endpoints
/wp-json/bulk-manager/v1/settings/wp-json/bulk-manager/v1/fields/wp-json/bulk-manager/v1/posts/wp-json/bulk-manager/v1/terms/wp-json/bulk-manager/v1/users
FAQ

Frequently Asked Questions about Bulk Manager