
Custom Referral Spam Blocker Security & Risk Analysis
wordpress.org/plugins/custom-referral-spam-blockerCustom Referral Spam Blocker gives you the control to ensure that dishonest referral sources are blocked from Google Analytics.
Is Custom Referral Spam Blocker Safe to Use in 2026?
Generally Safe
Score 85/100Custom Referral Spam Blocker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'custom-referral-spam-blocker' v1.4.6 exhibits a generally good security posture, with no known critical or high-severity vulnerabilities in its history and a strong adherence to secure coding practices regarding SQL queries. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface, which is a positive indicator. However, the static analysis reveals some areas of concern that temper this positive outlook. Notably, the presence of unsanitized paths in the taint analysis, despite not reaching critical or high severity, suggests a potential for unintended file access or manipulation if exploited. Furthermore, the output escaping is only 52% proper, indicating a risk of cross-site scripting (XSS) vulnerabilities, especially if dynamic content is being outputted without sufficient sanitization. The file operations and external HTTP requests, while not inherently vulnerable, are entry points that require careful monitoring and secure implementation. Given the lack of historical vulnerabilities, it appears the developers have a generally good track record, but the static analysis flags specific areas for improvement to ensure a robust security posture.
Key Concerns
- Unsanitized paths found in taint analysis
- Low percentage of properly escaped output
- No capability checks found
- No nonce checks found
Custom Referral Spam Blocker Security Vulnerabilities
Custom Referral Spam Blocker Code Analysis
Output Escaping
Data Flow Analysis
Custom Referral Spam Blocker Attack Surface
WordPress Hooks 8
Maintenance & Trust
Custom Referral Spam Blocker Maintenance & Trust
Maintenance Signals
Community Trust
Custom Referral Spam Blocker Alternatives
Analytics Spam Blocker
analytics-spam-blocker
Prevent referrer spam from affecting your website analytics. Easily create a blocklist and receive new domains weekly to stay on top of the issue.
Bot Block – Stop Spam Referrals in Google Analytics
bot-block-stop-spam-google-analytics-referrals
Block spam referrals showing in Google Analytics and save bandwidth. Central database of sites, ability to add custom URL's and stats.
WP referrer spam blacklist (fight 2040+ Referrer Spammers in (Google/Matomo) Analytics)
wp-referrer-spam-blacklist
WordPress plugin to fight with 2040+ referrer spammers (like semalt, buttons-for-website and many more).
Block Referral Spam
wp-block-referral-spam
This plugins blocks maximum Referral Spams. Now no more notice from Google and no more weird report in Google Analytics.
NO admin premium NAGS
no-aioseop-nags
Simply stop the abusive admin nags from All in One SEO plugin and as well from YOAST Seo! Plus: Add your own CSS to the Admin Area.
Custom Referral Spam Blocker Developer Profile
2 plugins · 310 total installs
How We Detect Custom Referral Spam Blocker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.