FortressDB Security & Risk Analysis

wordpress.org/plugins/fortressdb

High-speed, secure database plugin for WordPress form data

40 active installs v2.0.23 PHP 5.4+ WP 4.0+ Updated Jul 19, 2022
database-tables-charts-forminator-weforms-gravity-forms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FortressDB Safe to Use in 2026?

Generally Safe

Score 85/100

FortressDB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'fortressdb' v2.0.23 presents a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs and a significant portion of output being properly escaped are positive indicators. The fact that all identified SQL queries utilize prepared statements is a critical security best practice, mitigating the risk of SQL injection vulnerabilities. Furthermore, all identified AJAX entry points appear to have authentication checks, which is a key defense against unauthorized actions.

However, there are a few areas that warrant attention. The plugin performs file operations and external HTTP requests, which can be potential vectors for vulnerabilities if not handled with extreme care. The lack of any capability checks on the entry points is a significant concern, as it implies that any authenticated user could potentially trigger these AJAX actions, regardless of their role or permissions. While taint analysis found no issues, this might be due to the limited scope of analysis performed. The vulnerability history being clean is encouraging but does not guarantee future safety.

In conclusion, 'fortressdb' v2.0.23 demonstrates good fundamental security practices, particularly regarding SQL queries and basic authentication on AJAX handlers. The primary weakness lies in the absence of capability checks on its entry points, leaving potential for privilege escalation or unauthorized access to features. The file operations and external requests also represent areas where diligent review is recommended to ensure no exploitable logic exists.

Key Concerns

  • No capability checks on entry points
  • Significant portion of output unescaped
  • Performs file operations
  • Performs external HTTP requests
Vulnerabilities
None known

FortressDB Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FortressDB Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
30 escaped
Nonce Checks
3
Capability Checks
0
File Operations
3
External Requests
4
Bundled Libraries
0

Output Escaping

65% escaped46 total outputs
Attack Surface

FortressDB Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_fortressdb_get_current_userplugin.php:917
noprivwp_ajax_fortressdb_get_current_userplugin.php:918
authwp_ajax_fortressdb_api_backendplugin.php:919
noprivwp_ajax_fortressdb_api_backendplugin.php:920
authwp_ajax_fortressdb_support_formplugin.php:921
WordPress Hooks 10
filterweforms_integrationsaddons\weforms\fortressdb.php:28
filterfortressdb_api_request_headersincludes\class-fortressdb-api.php:61
filterhttp_headers_useragentincludes\class-fortressdb-api.php:62
actionenqueue_block_editor_assetsplugin.php:909
actionadmin_menuplugin.php:910
actionadmin_bar_menuplugin.php:911
actionadmin_enqueue_scriptsplugin.php:912
actionwp_enqueue_scriptsplugin.php:913
actionplugins_loadedplugin.php:914
actionclear_auth_cookieplugin.php:928
Maintenance & Trust

FortressDB Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 19, 2022
PHP min version5.4
Downloads5K

Community Trust

Rating80/100
Number of ratings4
Active installs40
Alternatives

FortressDB Alternatives

No alternatives data available yet.

Developer Profile

FortressDB Developer Profile

FortressDB

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FortressDB

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fortressdb/build/fortressdb_blocks.js/wp-content/plugins/fortressdb/build/fdblib.asset.php/wp-content/plugins/fortressdb/build/fdblib.js/wp-content/plugins/fortressdb/build/fdblib-components-vendors.css/wp-content/plugins/fortressdb/build/fdblib-components-vendors.js/wp-content/plugins/fortressdb/build/fdblib-components.css/wp-content/plugins/fortressdb/build/fdblib-components.js/wp-content/plugins/fortressdb/build/fortressdb.asset.php+13 more
Script Paths
/wp-content/plugins/fortressdb/build/fortressdb_blocks.js/wp-content/plugins/fortressdb/build/fdblib.js/wp-content/plugins/fortressdb/build/fdblib-components-vendors.js/wp-content/plugins/fortressdb/build/fdblib-components.js/wp-content/plugins/fortressdb/build/fortressdb_vendors.js/wp-content/plugins/fortressdb/build/fortressdb.js+4 more
Version Parameters
fortressdb/build/fortressdb_blocks.js?ver=fortressdb/build/fdblib.js?ver=fortressdb/build/fdblib-components-vendors.css?ver=fortressdb/build/fdblib-components-vendors.js?ver=fortressdb/build/fdblib-components.css?ver=fortressdb/build/fdblib-components.js?ver=fortressdb/build/fortressdb_vendors.js?ver=fortressdb/build/fortressdb.css?ver=fortressdb/build/fortressdb.js?ver=fortressdb/build/pages/fdblib-page-connect.css?ver=fortressdb/build/pages/fdblib-page-connect.js?ver=fortressdb/build/fortressdb_page_settings.js?ver=fortressdb/build/fortressdb_page_support.css?ver=fortressdb/build/fortressdb_page_support.js?ver=fortressdb/build/fortressdb_page_api.css?ver=fortressdb/build/fortressdb_page_api.js?ver=

HTML / DOM Fingerprints

CSS Classes
fdblib-componentfdblib-iconfdblib-input
Data Attributes
data-fdblib-element
JS Globals
fortressdbfortressdb_options
FAQ

Frequently Asked Questions about FortressDB