
dpaBottomofPostPage Security & Risk Analysis
wordpress.org/plugins/dpabottomofpostpageThis plugin can add several messages or adverts to the bottom of every WordPress post and page and now messages can be shown in in Home, Category & …
Is dpaBottomofPostPage Safe to Use in 2026?
Generally Safe
Score 85/100dpaBottomofPostPage has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'dpabottomofpostpage' plugin exhibits a mixed security posture. While it boasts zero known CVEs and a clean vulnerability history, suggesting a generally stable codebase over time, the static analysis reveals significant concerns. The presence of 39 dangerous function calls, particularly `unserialize`, combined with taint analysis showing flows with unsanitized paths, is a major red flag. Specifically, a high-severity taint flow indicates a potential for malicious data manipulation. The fact that 95% of output is not properly escaped presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks on entry points, which are zero in this case, offers no protection against unauthorized actions if any were to be discovered. While the plugin's minimal attack surface and exclusive use of prepared statements for SQL are positive attributes, the identified issues with data sanitization, output escaping, and the inherent risks of deserialization present a substantial security risk that requires immediate attention.
Key Concerns
- Unsanitized path in taint flow (high severity)
- Dangerous function 'unserialize' present
- Insufficient output escaping (95% unescaped)
- No nonce checks on entry points
- No capability checks on entry points
dpaBottomofPostPage Security Vulnerabilities
dpaBottomofPostPage Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
dpaBottomofPostPage Attack Surface
WordPress Hooks 11
Maintenance & Trust
dpaBottomofPostPage Maintenance & Trust
Maintenance Signals
Community Trust
dpaBottomofPostPage Alternatives
Ninja Footers
ninja-footers-lite
Create customizable footers for your posts.
Posts Footer Manager
intelly-posts-footer-manager
Clean the mess after your content! Organize your post's footer, insert what you want, order elements, create groups for specific categories.
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
dpaBottomofPostPage Developer Profile
2 plugins · 40 total installs
How We Detect dpaBottomofPostPage
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dpabottomofpostpage/spmybpz_zbopp_setup_form.js/wp-content/plugins/dpabottomofpostpage/spmybpz_zbopp_setup_form.css/wp-content/plugins/dpabottomofpostpage/spmybpz_zbopp_setup_form.jsdpabottomofpostpage/spmybpz_zbopp_setup_form.css?ver=dpabottomofpostpage/spmybpz_zbopp_setup_form.js?ver=HTML / DOM Fingerprints
spmybpz_zbopp_setup_form_wrap<!-- dpabottomofpostpage setup form --><!-- end of dpabottomofpostpage setup form -->data-tab-idspmybpz_zbopp_var