ClickCease Click Fraud Protection Security & Risk Analysis

wordpress.org/plugins/clickcease-click-fraud-protection

Protect your website and ad campaigns from bots, competitors, and click fraud with ClickCease's advanced fraud prevention and real-time monitoring.

10K active installs v3.2.13 PHP 5.6+ WP 5.6+ Updated Jul 21, 2025
bot-protectionclick-fraudclickceasefraud-protectionwebsite-protection
99
A · Safe
CVEs total2
Unpatched0
Last CVEMay 6, 2024
Download
Safety Verdict

Is ClickCease Click Fraud Protection Safe to Use in 2026?

Generally Safe

Score 99/100

ClickCease Click Fraud Protection has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: May 6, 2024Updated 8mo ago
Risk Assessment

The ClickCease Click Fraud Protection plugin v3.2.13 exhibits a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling, exclusively using prepared statements and having no known unpatched CVEs. The absence of raw SQL queries and file operations is also a strong indicator of secure coding in those areas. However, significant concerns arise from the attack surface, with all six identified AJAX handlers lacking authentication checks. This creates a substantial risk of unauthorized actions being performed by unauthenticated users. Additionally, the taint analysis revealed three flows with unsanitized paths, although they did not reach critical or high severity, they still represent a potential vector for data manipulation or unintended behavior. The vulnerability history, while showing no currently unpatched issues, includes two past medium severity CVEs related to Improper Access Control and CSRF, suggesting a pattern of past security weaknesses that require ongoing vigilance.

Key Concerns

  • 6 AJAX handlers without authentication checks
  • 3 Taint flows with unsanitized paths
  • Past medium severity CVEs (Improper Access Control, CSRF)
  • Output escaping only 59% properly escaped
  • Only 3 capability checks for 6 entry points
Vulnerabilities
2

ClickCease Click Fraud Protection Security Vulnerabilities

CVEs by Year

2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2023-6810medium · 4.3Improper Access Control

ClickCease Click Fraud Protection <= 3.2.4 - Improper Authorization to sensitive information exposure via get_settings

May 6, 2024 Patched in 3.2.5 (85d)
CVE-2024-33678medium · 4.3Cross-Site Request Forgery (CSRF)

ClickCease Click Fraud Protection <= 3.2.7 - Cross-Site Request Forgery

Apr 26, 2024 Patched in 3.2.8 (137d)
Code Analysis
Analyzed Mar 16, 2026

ClickCease Click Fraud Protection Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
13 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
8
Bundled Libraries
0

Output Escaping

59% escaped22 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
save_settings (classes\routes.php:54)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

ClickCease Click Fraud Protection Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_get_settingsclasses\routes.php:12
authwp_ajax_update_whitelistclasses\routes.php:13
authwp_ajax_save_settingsclasses\routes.php:14
authwp_ajax_updateInstallClickFraudclasses\routes.php:15
authwp_ajax_validate_clickcease_responseclickcease.php:49
noprivwp_ajax_validate_clickcease_responseclickcease.php:50
WordPress Hooks 8
actionplugins_loadedclickcease.php:20
actionwp_enqueue_scriptsclickcease.php:42
actionsend_headersclickcease.php:46
actionwp_enqueue_scriptsclickcease.php:47
actionwp_body_openclickcease.php:48
actionadmin_menuclickcease.php:241
actionadmin_initclickcease.php:244
actionadmin_enqueue_scriptsclickcease.php:253
Maintenance & Trust

ClickCease Click Fraud Protection Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 21, 2025
PHP min version5.6
Downloads261K

Community Trust

Rating66/100
Number of ratings7
Active installs10K
Developer Profile

ClickCease Click Fraud Protection Developer Profile

eranfl

2 plugins · 11K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
111 days
View full developer profile
Detection Fingerprints

How We Detect ClickCease Click Fraud Protection

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clickcease-click-fraud-protection/clickcease-script.js/wp-content/plugins/clickcease-click-fraud-protection/clickcease-styles.css
Script Paths
/wp-content/plugins/clickcease-click-fraud-protection/clickcease-script.js
Version Parameters
clickcease-click-fraud-protection/clickcease-script.js?ver=clickcease-click-fraud-protection/clickcease-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
clickcease-container
HTML Comments
<!-- Clickcease - Click Fraud Protection --><!-- Clickcease JS Script Start --><!-- Clickcease JS Script End --><!-- Clickcease CSS Script Start -->+5 more
Data Attributes
data-clickcease-iddata-clickcease-domaindata-clickcease-keydata-clickcease-api
JS Globals
clickcease_ajax_objectclickcease_wp_params
FAQ

Frequently Asked Questions about ClickCease Click Fraud Protection