Fetch SPAD Security & Risk Analysis

wordpress.org/plugins/fetch-spad

⚠️ DEPRECATED PLUGIN - PLEASE MIGRATE This plugin is being retired. Please use Fetch Meditation instead: https://wordpress.

40 active installs v1.4.0 PHP 8.1+ WP 6.2+ Updated Oct 21, 2025
nanarcotics-anonymousspadspiritual-principle-a-day
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fetch SPAD Safe to Use in 2026?

Generally Safe

Score 100/100

Fetch SPAD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin 'fetch-spad' v1.4.0 demonstrates a generally strong security posture based on the provided static analysis. The code adheres to several best practices, including 100% proper output escaping and the use of prepared statements for all SQL queries. The presence of a nonce check is also a positive indicator. The attack surface appears minimal, with only one shortcode identified and no unprotected entry points. Taint analysis revealed no issues, and there is no recorded vulnerability history.

However, a key concern is the complete absence of capability checks. While there are no identified unprotected AJAX handlers or REST API routes, the lack of capability checks on the shortcode or any other potential entry points means that any authenticated user, regardless of their role or permissions, could potentially interact with the plugin's functionality. This could lead to unintended consequences or information disclosure depending on what the shortcode does. The bundling of Guzzle, while common, also warrants attention to ensure it is kept updated to avoid potential downstream vulnerabilities if the library itself has known issues.

Overall, the plugin is well-implemented with respect to common web vulnerabilities like SQL injection and XSS. The primary weakness lies in the granular access control, or lack thereof, which is a significant oversight for any plugin interacting with user actions or data. The absence of past vulnerabilities is encouraging but should not lead to complacency, especially given the identified access control gap.

Key Concerns

  • Missing capability checks
  • Bundled library (Guzzle) without version info
Vulnerabilities
None known

Fetch SPAD Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fetch SPAD Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

100% escaped13 total outputs
Attack Surface

Fetch SPAD Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[spad] fetch-spad-plugin.php:82
WordPress Hooks 6
actioninitfetch-spad-plugin.php:51
actionadmin_noticesfetch-spad-plugin.php:52
actionadmin_menufetch-spad-plugin.php:77
actionadmin_initfetch-spad-plugin.php:78
actionadmin_enqueue_scriptsfetch-spad-plugin.php:79
actionwp_enqueue_scriptsfetch-spad-plugin.php:81
Maintenance & Trust

Fetch SPAD Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 21, 2025
PHP min version8.1
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Fetch SPAD Developer Profile

pjaudiomv

10 plugins · 370 total installs

99
trust score
Avg Security Score
98/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Fetch SPAD

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fetch-spad/css/fetch-spad.css
Script Paths
/wp-content/plugins/fetch-spad/js/fetch-spad.js
Version Parameters
fetch-spad/css/fetch-spad.css?ver=1.0.0fetch-spad/js/fetch-spad.js?ver=

HTML / DOM Fingerprints

CSS Classes
spadspad-rendered-elementspad-table
Data Attributes
id="spad-container"class="spad-rendered-element"id="spad-content-1"class="spad-rendered-element"id="spad-date"class="spad-rendered-element"+32 more
Shortcode Output
[spad]
FAQ

Frequently Asked Questions about Fetch SPAD