
RockPress Security & Risk Analysis
wordpress.org/plugins/ft-rockpressIntroducing the easiest way to display information from Rock RMS on your church WordPress site.
Is RockPress Safe to Use in 2026?
Generally Safe
Score 99/100RockPress has a strong security track record. Known vulnerabilities have been patched promptly.
The "ft-rockpress" v1.0.18 plugin exhibits a mixed security posture. While it scores well in terms of the absence of recorded CVEs and critical taint analysis findings, several concerning aspects emerge from the static analysis. A significant portion of its attack surface, specifically 6 out of 7 AJAX handlers, lacks proper authentication checks, presenting a substantial risk of unauthorized access and potential exploitation of underlying functionalities. The presence of SQL queries that are not prepared is another weakness, increasing the susceptibility to SQL injection attacks.
Despite these concerns, the plugin demonstrates good practices in output escaping, with 89% of outputs properly handled. The lack of known vulnerabilities in its history suggests a generally well-maintained codebase or a lack of past discovery. However, the identified unprotected AJAX endpoints are a critical area that needs immediate attention, as they represent readily accessible entry points for attackers. The plugin's strengths lie in its lack of critical static analysis issues beyond the AJAX handlers and its good output escaping. The weaknesses are primarily the unprotected AJAX endpoints and the use of raw SQL queries, which, if exploited, could lead to severe security breaches.
Key Concerns
- Unprotected AJAX handlers
- SQL queries not using prepared statements
RockPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
RockPress <= 1.0.17 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via AJAX Actions
RockPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
RockPress Attack Surface
AJAX Handlers 7
WordPress Hooks 41
Scheduled Events 2
Maintenance & Trust
RockPress Maintenance & Trust
Maintenance Signals
Community Trust
RockPress Alternatives
Church Data Connect for Church Community Builder
ccbpress-core
Introducing the easiest way to display information from Church Community Builder (formerly Church Community Builder) on your church WordPress site.
Spiritual Gifts Test
spiritual-gifts-test
Spiritual Gifts and S.H.A.P.E. Test to help church attendees find their place of service in the local church and other service organizations.
Church Content – Sermons, Events and More
church-theme-content
Provides an interface for managing sermons, events, people and locations. A compatible theme is required for presenting content from these church-cent …
Advanced Sermons
advanced-sermons
Elevate your church's digital outreach with audio/video sermons, organized speakers, and series management.
Church Admin
church-admin
Organise and communicate church life, with associated Android and iOS app for your congregation.
RockPress Developer Profile
3 plugins · 310 total installs
How We Detect RockPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ft-rockpress/assets/css/display.cssrockpress/assets/css/display.css?ver=