
WebDefender Security – Protection & AntiSpam Security & Risk Analysis
wordpress.org/plugins/cwis-antivirus-malware-detectedPRO Security – Antivirus Scanner, 2-Layer Protection Hide Security, Brute Force Security & Antispam, Security Website and Security Hardening.
Is WebDefender Security – Protection & AntiSpam Safe to Use in 2026?
Generally Safe
Score 100/100WebDefender Security – Protection & AntiSpam has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cwis-antivirus-malware-detected" plugin v5.0.2.1 exhibits a concerning security posture due to a significant number of unprotected entry points. All identified AJAX handlers (4) and REST API routes (2) lack proper authentication or permission checks, exposing the plugin to potential unauthorized access and manipulation. While the plugin demonstrates good practices in SQL query preparation (77%) and output escaping (93%), these strengths are heavily overshadowed by the critical lack of security on its primary interaction points.
The static analysis reveals that all 6 identified entry points are unprotected, presenting a substantial attack surface. The presence of the `unserialize` function among dangerous functions is a potential risk, especially when coupled with unsanitized input, although the taint analysis did not report any critical or high-severity flows. The absence of nonce checks on AJAX handlers is a particularly glaring omission, a standard security measure that should be implemented to prevent CSRF attacks.
Furthermore, the plugin has a clean vulnerability history with no recorded CVEs. This might suggest a relatively well-maintained codebase in the past or that vulnerabilities haven't been publicly disclosed. However, the lack of historical issues does not negate the present security weaknesses identified in the code. The plugin's strengths in output escaping and prepared statements are commendable but insufficient to mitigate the risks posed by unprotected AJAX and REST API endpoints.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Dangerous function 'unserialize' used
- No nonce checks on AJAX
- Taint analysis: 3 flows with unsanitized paths
WebDefender Security – Protection & AntiSpam Security Vulnerabilities
WebDefender Security – Protection & AntiSpam Release Timeline
WebDefender Security – Protection & AntiSpam Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WebDefender Security – Protection & AntiSpam Attack Surface
AJAX Handlers 4
REST API Routes 2
WordPress Hooks 16
Maintenance & Trust
WebDefender Security – Protection & AntiSpam Maintenance & Trust
Maintenance Signals
Community Trust
WebDefender Security – Protection & AntiSpam Alternatives
MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall
malcare-security
Get Bulletproof Security for your WordPress site. WordPress security plugin packed with comprehensive Firewall, malware scanner, cleaner & more.
SecuPress with Simple SSL – Simple and Performant Security
secupress
Protect your WordPress with SecuPress, analyze and ensure the safety of your website daily.
Quttera ThreatSign – Web Malware Scanner for WordPress
quttera-web-malware-scanner
WordPress multi-level security scanner detecting malware, 0-day threats, brute-force attacks, bot attacks, and unauthorized admin changes.
SP Move Login
sf-move-login
Move your WordPress login page to protect it from bots. This plugin contains the Move Login module from SecuPress. Other security modules are availabl …
Virusdie – One-click website security
virusdie
Malware scanning & removal, website hardening, patching vulnerabilities, real-time protection against online attacks, blacklist monitoring in a click!
WebDefender Security – Protection & AntiSpam Developer Profile
1 plugin · 1K total installs
How We Detect WebDefender Security – Protection & AntiSpam
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cwis-antivirus-malware-detected/cwis-scan/assets/css/backend.css/wp-content/plugins/cwis-antivirus-malware-detected/cwis-scan/assets/css/backend-dark-theme.css/wp-content/plugins/cwis-antivirus-malware-detected/cwis-scan/assets/css/frontend.css/wp-content/plugins/cwis-antivirus-malware-detected/cwis-scan/assets/js/backend.jsWebDefender Security – Protection & AntiSpam/wp-content/plugins/cwis-antivirus-malware-detected/cwis-scan/assets/js/backend.jscwis-antivirus-malware-detected/cwis-scan/assets/css/backend.css?ver=cwis-antivirus-malware-detected/cwis-scan/assets/css/backend-dark-theme.css?ver=cwis-antivirus-malware-detected/cwis-scan/assets/css/frontend.css?ver=cwis-antivirus-malware-detected/cwis-scan/assets/js/backend.js?ver=HTML / DOM Fingerprints
cwis-dashboard-widget-bodywd-antispam-noticewd-block-ui-spinner-wrap<!-- Cwis dashboard --><!-- Security Dashboard -->data-wd-plugin-versioncwis_dataWdapp/wp-json/wdapp/v1/installer/wp-json/wdapp/v1/scanner/wp-json/wdapp/v1/check_server_status