DazeStack Bulk Plugin Manager Security & Risk Analysis

wordpress.org/plugins/dazestack-bulk-plugin-manager

The most beautiful, native Mac-like bulk plugin manager for WordPress. Import, export, and provision plugin stacks in one streamlined workspace.

0 active installs v0.0.1 PHP 7.4+ WP 6.0+ Updated Unknown
admin-toolsautomationbulk-installmigrationplugin-management
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DazeStack Bulk Plugin Manager Safe to Use in 2026?

Generally Safe

Score 100/100

DazeStack Bulk Plugin Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'dazestack-bulk-plugin-manager' v0.0.1 exhibits a concerning security posture due to a significant number of unprotected entry points. All 21 identified entry points, consisting of 19 AJAX handlers and 2 REST API routes, lack authentication checks. This creates a wide attack surface where any unauthenticated user could potentially interact with sensitive plugin functionalities. While the plugin demonstrates good practices in SQL query handling and output escaping, the absence of proper authorization on such a large number of entry points presents a substantial risk. The lack of any recorded vulnerability history might suggest it's a relatively new or less exploited plugin, but this does not negate the inherent risks presented by the exposed attack surface. A balanced conclusion is that while code quality in specific areas like SQL and output escaping is good, the critical oversight in securing its numerous entry points makes this plugin a high-risk candidate for exploitation.

Key Concerns

  • AJAX handlers without auth checks
  • REST API routes without permission callbacks
Vulnerabilities
None known

DazeStack Bulk Plugin Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DazeStack Bulk Plugin Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
70 escaped
Nonce Checks
20
Capability Checks
2
File Operations
2
External Requests
4
Bundled Libraries
0

Output Escaping

100% escaped70 total outputs
Attack Surface
21 unprotected

DazeStack Bulk Plugin Manager Attack Surface

Entry Points21
Unprotected21

AJAX Handlers 19

authwp_ajax_dsbpm_preflightincludes\class-dsbpm-admin.php:40
authwp_ajax_dsbpm_payloadincludes\class-dsbpm-admin.php:41
authwp_ajax_dsbpm_simulateincludes\class-dsbpm-admin.php:42
authwp_ajax_dsbpm_vuln_checkincludes\class-dsbpm-admin.php:43
authwp_ajax_dsbpm_plugins_listincludes\class-dsbpm-admin.php:44
authwp_ajax_dsbpm_save_noteincludes\class-dsbpm-admin.php:45
authwp_ajax_dsbpm_toggle_pinincludes\class-dsbpm-admin.php:46
authwp_ajax_dsbpm_enqueueincludes\class-dsbpm-admin.php:47
authwp_ajax_dsbpm_installincludes\class-dsbpm-admin.php:48
authwp_ajax_dsbpm_metricsincludes\class-dsbpm-admin.php:49
authwp_ajax_dsbpm_resolve_slugincludes\class-dsbpm-admin.php:50
authwp_ajax_dsbpm_sort_queueincludes\class-dsbpm-admin.php:51
authwp_ajax_dsbpm_deactivateincludes\class-dsbpm-admin.php:52
authwp_ajax_dsbpm_deleteincludes\class-dsbpm-admin.php:53
authwp_ajax_dsbpm_deactivate_allincludes\class-dsbpm-admin.php:54
authwp_ajax_dsbpm_delete_allincludes\class-dsbpm-admin.php:55
authwp_ajax_dsbpm_remote_listincludes\class-dsbpm-admin.php:56
authwp_ajax_dsbpm_partner_offersincludes\class-dsbpm-admin.php:57
authwp_ajax_dsbpm_store_credentialsincludes\class-dsbpm-admin.php:58

REST API Routes 2

GET/wp-json/dazestack/v1/healthincludes\class-dsbpm-admin.php:141
GET/wp-json/dazestack/v1/abilitiesincludes\class-dsbpm-admin.php:151
WordPress Hooks 7
actionplugins_loadedbulk-plugin-manager.php:39
actionplugins_loadedincludes\class-dsbpm-admin.php:30
actionadmin_menuincludes\class-dsbpm-admin.php:34
actionadmin_enqueue_scriptsincludes\class-dsbpm-admin.php:35
actionadmin_post_dsbpm_exportincludes\class-dsbpm-admin.php:36
actiondsbpm_run_installincludes\class-dsbpm-admin.php:61
actionrest_api_initincludes\class-dsbpm-admin.php:64
Maintenance & Trust

DazeStack Bulk Plugin Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads207

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

DazeStack Bulk Plugin Manager Developer Profile

Ashish Dung Dung

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DazeStack Bulk Plugin Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dazestack-bulk-plugin-manager/assets/admin.css/wp-content/plugins/dazestack-bulk-plugin-manager/assets/vendor/read-excel-file.min.js/wp-content/plugins/dazestack-bulk-plugin-manager/assets/admin.js/wp-content/plugins/dazestack-bulk-plugin-manager/assets/data/partner-offers.xlsx/wp-content/plugins/dazestack-bulk-plugin-manager/assets/data/partner-offers.csv
Script Paths
/wp-content/plugins/dazestack-bulk-plugin-manager/assets/vendor/read-excel-file.min.js/wp-content/plugins/dazestack-bulk-plugin-manager/assets/admin.js
Version Parameters
dazestack-bulk-plugin-manager/assets/admin.css?ver=dazestack-bulk-plugin-manager/assets/vendor/read-excel-file.min.js?ver=dazestack-bulk-plugin-manager/assets/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
DSBPM_DATA
REST Endpoints
/wp-json/dazestack/v1/health/wp-json/dazestack/v1/abilities
FAQ

Frequently Asked Questions about DazeStack Bulk Plugin Manager