CODEC Sponsored Content Security & Risk Analysis

wordpress.org/plugins/codec-sponsored-content

Premium monetizing system for quality blogs & publications (English-language websites only.) Generate revenue by displaying a widget with manually …

10 active installs v3.0.0 PHP 5.2.4+ WP 4.1+ Updated Jan 11, 2024
adadsenseadvertisingmonetizationrevenue
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CODEC Sponsored Content Safe to Use in 2026?

Generally Safe

Score 85/100

CODEC Sponsored Content has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "codec-sponsored-content" v3.0.0 plugin exhibits a significant security concern due to its unprotected AJAX handlers. While the plugin demonstrates good practices in its handling of SQL queries, using prepared statements exclusively, and has no recorded vulnerability history, the lack of authentication and capability checks on all its AJAX entry points creates a wide attack surface. This means any unauthenticated user could potentially trigger these AJAX actions, leading to unintended consequences. The taint analysis revealing unsanitized paths further exacerbates this risk, indicating that user-supplied data might be processed without proper validation, although no critical or high-severity issues were directly identified in the taint flows. The high percentage of improperly escaped output is also a notable weakness that could contribute to cross-site scripting (XSS) vulnerabilities if these outputs are rendered directly in the browser.

In conclusion, the plugin's strength lies in its secure database interactions and clean vulnerability history. However, the pervasive absence of security checks on its AJAX endpoints and the presence of unsanitized paths in taint flows are critical security oversights. The poorly escaped output further compounds these risks. While there are no known CVEs, the current implementation presents a clear opportunity for attackers to exploit these unprotected entry points, making it a plugin that requires immediate attention for security hardening, particularly regarding AJAX request verification and output sanitization.

Key Concerns

  • AJAX handlers without auth checks
  • Unsanitized paths in taint analysis
  • Low percentage of properly escaped output
  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
Vulnerabilities
None known

CODEC Sponsored Content Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CODEC Sponsored Content Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

19% escaped26 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
cppp_auto_widget_enable (codec-sponsored-content.php:134)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

CODEC Sponsored Content Attack Surface

Entry Points8
Unprotected8

AJAX Handlers 8

authwp_ajax_cppp_page_statuscodec-sponsored-content.php:124
authwp_ajax_cppp_create_pagecodec-sponsored-content.php:125
authwp_ajax_cppp_paypalcodec-sponsored-content.php:126
authwp_ajax_cppp_empty_widgetscodec-sponsored-content.php:127
authwp_ajax_cppp_site_urlcodec-sponsored-content.php:128
authwp_ajax_cppp_auto_widget_enablecodec-sponsored-content.php:129
authwp_ajax_cppp_wizzard_finishcodec-sponsored-content.php:130
authwp_ajax_cppp_disable_auto_widgetcodec-sponsored-content.php:131
WordPress Hooks 7
actionadmin_headcodec-sponsored-content.php:75
filterwp_headcodec-sponsored-content.php:101
filterscript_loader_tagcodec-sponsored-content.php:109
filterscript_loader_tagcodec-sponsored-content.php:117
actionadmin_menucodec-sponsored-content.php:121
filterthe_contentcodec-sponsored-content.php:359
actionwidgets_initwidget.php:11
Maintenance & Trust

CODEC Sponsored Content Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 11, 2024
PHP min version5.2.4
Downloads3K

Community Trust

Rating74/100
Number of ratings3
Active installs10
Developer Profile

CODEC Sponsored Content Developer Profile

codecprime

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CODEC Sponsored Content

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/codec-sponsored-content/images/codec-logo-small.png
Script Paths
/wp-content/plugins/codec-sponsored-content/js/codec.js/wp-content/plugins/codec-sponsored-content/js/codec-admin.js
Version Parameters
codec-sponsored-content/js/codec.js?ver=codec-sponsored-content/js/codec-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
update-nagnotice-warninginline
JS Globals
cppp_admin_ajax_urlcodec_publisher_idcodec_admin_ajax_urlcodec_auto_widget_statuscodec_auto_widget_unitscodec_paypal_status+4 more
REST Endpoints
/wp-json/codec-sponsored-content/v1/settings/wp-json/codec-sponsored-content/v1/sync
FAQ

Frequently Asked Questions about CODEC Sponsored Content