
CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard Security & Risk Analysis
wordpress.org/plugins/code-monkeys-proposalsEasily create, save and convert client proposals to PDF from your Wordpress admin dashboard.
Is CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard Safe to Use in 2026?
Generally Safe
Score 85/100CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "code-monkeys-proposals" plugin, in version 1.0.1, exhibits a generally good security posture with several strong practices in place. The complete absence of known CVEs and a clean vulnerability history suggest a well-maintained and secure plugin. The static analysis further reinforces this, showing no critical or high-severity taint flows, no dangerous functions, and all SQL queries utilize prepared statements. The presence of nonce checks on AJAX handlers is also a positive indicator.
However, there are areas for improvement. While the attack surface is limited to 8 AJAX handlers, none of them have explicit capability checks. This means that any authenticated user, regardless of their role or permissions, could potentially interact with these handlers. Additionally, a significant portion (50%) of the plugin's output is not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without sanitization.
In conclusion, the plugin is largely secure due to its clean history and robust handling of SQL and taint analysis. The primary concerns are the lack of capability checks on AJAX actions and the unescaped output. Addressing these would further strengthen the plugin's security.
Key Concerns
- AJAX handlers lack capability checks
- Significant unescaped output detected
CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard Security Vulnerabilities
CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard Code Analysis
Output Escaping
Data Flow Analysis
CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard Attack Surface
AJAX Handlers 8
WordPress Hooks 4
Maintenance & Trust
CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard Maintenance & Trust
Maintenance Signals
Community Trust
CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard Alternatives
Quotes for WooCommerce
quotes-for-woocommerce
This plugin allows the site admin the ability to accept quote requests for products. Prices can be hidden. No payments will be taken at Checkout.
AWcode Toolkit
awcode-toolkit
AWcode Toolkit provides a collection of useful tools and functions for Wordpress site owners
Etoile Theme Companion
etoile-theme-companion
Companion plugin for themes from Etoile Web Design, such as the Ultimate Showcase theme.
GW Elementor Addons
gw-elementor-addons
GW Elementor Addons – Take your Elementor designs to the next level with 40+ premium widgets, 120+ templates, and many more.
Designer Blocks for Block Editor by Weaver
blocks-by-weaver
Discover the power of the Block Editor! This plugin adds Designer Blocks that make it easy to add Images, Text, and Parallax.
CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard Developer Profile
2 plugins · 910 total installs
How We Detect CODE MONKEYS PROPOSALS – Easily create client proposals from your WordPress admin dashboard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/code-monkeys-proposals/css/admin-style.css/wp-content/plugins/code-monkeys-proposals/js/admin-script.js/wp-content/plugins/code-monkeys-proposals/js/admin-script.jscmProposalsAdminStylecmProposalsAdminScriptHTML / DOM Fingerprints
cm-proposals-accordian-tab-linkcm-proposals-tour-tab-contentcm-proposals-tab-content-topcm-proposals-toggle-buttoncm-proposals-switchcm-proposals-slidercm-proposals-templatecm-proposals-template-top+23 more REQUIRE ENQUEUE FILECreated by Code Monkeys LLChttp://www.codemonkeysllc.comUser: Spencer+30 moredata="tour-tab-class="cm-proposals-accordian-tab-link"class="cm-proposals-tour-tab-content"class="cm-proposals-tab-content-top"class="cm-proposals-toggle-button"class="cm-proposals-switch"+33 morecmProposalsAdminScriptajax