
D64 LSR-Stopper Security & Risk Analysis
wordpress.org/plugins/d64-lsr-stopperMit diesem Plugin verhinderst du Verlinkungen zu Medien, deren Verlage das Leistungsschutzrecht unterstützen bzw. in Anspruch nehmen.
Is D64 LSR-Stopper Safe to Use in 2026?
Generally Safe
Score 85/100D64 LSR-Stopper has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "d64-lsr-stopper" v1.0.4 reveals a generally secure foundation, with no identified vulnerabilities in its limited attack surface. The plugin does not expose any AJAX handlers, REST API routes, shortcodes, or cron events without proper authorization checks, which is a significant strength. Furthermore, all SQL queries are properly prepared, indicating good database interaction practices. The absence of any known CVEs in its vulnerability history is also a positive sign, suggesting a history of responsible development.
However, there are notable concerns. The most critical finding is that 100% of the output from the plugin is not properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the WordPress admin area or even the front-end of a website. The plugin also performs a file operation and an external HTTP request, which, without further context on their implementation, could potentially be exploited if not handled with strict sanitization and validation. The complete lack of nonce and capability checks on its entry points, while currently not an issue due to the absence of such points, highlights a potential gap in future extensibility if new entry points are added without security considerations.
In conclusion, while "d64-lsr-stopper" v1.0.4 benefits from a minimal attack surface and secure SQL handling, the unescaped output is a critical weakness that requires immediate attention. The vulnerability history is clean, which is encouraging, but the static analysis clearly points to a specific, high-impact vulnerability that could be exploited.
Key Concerns
- Output is not properly escaped
- Capability checks are missing
- Nonce checks are missing
D64 LSR-Stopper Security Vulnerabilities
D64 LSR-Stopper Code Analysis
SQL Query Safety
Output Escaping
D64 LSR-Stopper Attack Surface
WordPress Hooks 4
Maintenance & Trust
D64 LSR-Stopper Maintenance & Trust
Maintenance Signals
Community Trust
D64 LSR-Stopper Alternatives
ActiveCampaign – The autonomous marketing platform
activecampaign-subscription-forms
Add ActiveCampaign contact forms and live chat to any post, page, or sidebar. Also enable ActiveCampaign site tracking for your WordPress blog.
Featured Images in RSS for Mailchimp & More
featured-images-for-rss-feeds
Send images to RSS instantly for free. Output blog or WooCommerce photos to Mailchimp RSS email campaigns, ActiveCampaign, Hubspot, Feedly and more.
CartBounty – Save and recover abandoned carts for WooCommerce
woo-save-abandoned-carts
Save abandoned carts and send automated abandoned cart recovery messages. Get more leads, reduce cart abandonment, and increase sales.
ActiveCampaign for WooCommerce
activecampaign-for-woocommerce
https://youtu.be/wHPrLFXQTgQ
Finale Lite – Sales Countdown Timer & Discount for WooCommerce
finale-woocommerce-sales-countdown-timer-discount
Finale lets you create scheduled one time or recurring campaigns. It induces urgency with visual elements such as Countdown Timer and Counter Bar to m …
D64 LSR-Stopper Developer Profile
2 plugins · 30 total installs
How We Detect D64 LSR-Stopper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<p><strong>Schutz gegen das Leistungschutzrecht ist aktiv.</strong>