
Anti-Malware Security and Brute-Force Firewall Security & Risk Analysis
wordpress.org/plugins/gotmlsThis Anti-Malware scanner searches for Malware, Viruses, and other security threats and vulnerabilities on your server and it helps you fix them.
Is Anti-Malware Security and Brute-Force Firewall Safe to Use in 2026?
Mostly Safe
Score 81/100Anti-Malware Security and Brute-Force Firewall is generally safe to use. 10 past CVEs were resolved.
The "gotmls" plugin v4.23.88 exhibits a concerning security posture despite some positive indicators. While it boasts a small attack surface with no unprotected entry points and a high percentage of SQL queries using prepared statements, several critical vulnerabilities in its code and taint analysis are deeply worrying. The presence of four "unserialize" calls is a significant red flag, especially when combined with a high number of unsanitized paths identified in the taint analysis. This suggests a strong possibility of deserialization vulnerabilities, where malicious data could lead to code execution. Furthermore, the plugin's historical vulnerability record, with nine known CVEs including one critical and two high-severity issues, points to a recurring pattern of security weaknesses. The types of past vulnerabilities, such as Code Injection, Deserialization of Untrusted Data, XSS, and CSRF, align with the risks suggested by the static analysis. The lack of nonce checks is another notable deficiency. Overall, while the plugin attempts to use prepared statements and has a limited attack surface, the identified risks in deserialization, unsanitized data flows, and historical vulnerabilities paint a picture of a plugin that requires immediate attention and remediation.
Key Concerns
- Critical taint flow detected
- High severity taint flow detected
- Dangerous function 'unserialize' used
- Low percentage of properly escaped output
- No nonce checks present
- Total of 9 known CVEs
- Historical critical vulnerability
- Historical high severity vulnerabilities
Anti-Malware Security and Brute-Force Firewall Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Anti-Malware Security and Brute-Force Firewall <= 4.23.87 - Authenticated (Contributor+) PHP Object Injection
Anti-Malware Security and Brute-Force Firewall <= 4.23.81 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Read
Anti-Malware Security and Brute-Force Firewall <= 4.21.96 - Unauthenticated Remote Code Execution
Anti-Malware Security and Brute-Force Firewall <= 4.21.85 - Authenticated (Admin+) PHP Object Injection
Anti-Malware Security and Brute-Force Firewall <= 4.20.95 - Reflected Cross-Site Scripting
Anti-Malware Security and Brute-Force Firewall <= 4.21.74 - Reflected Cross-Site Scripting
Anti-Malware Security and Brute-Force Firewall <= 4.20.93 - Reflected Cross-Site Scripting
Anti-Malware Security and Brute-Force Firewall <= 4.15.17 - Cross-Site Scripting
Anti-Malware Security and Brute-Force Firewall <= 4.15.22 - Cross-Site Request Forgery
Anti-Malware Security and Brute-Force Firewall <= 4.15.22 - Cross-Site Scripting
Anti-Malware Security and Brute-Force Firewall Release Timeline
Anti-Malware Security and Brute-Force Firewall Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Anti-Malware Security and Brute-Force Firewall Attack Surface
Shortcodes 2
WordPress Hooks 15
Maintenance & Trust
Anti-Malware Security and Brute-Force Firewall Maintenance & Trust
Maintenance Signals
Community Trust
Anti-Malware Security and Brute-Force Firewall Alternatives
Protector – Malware Removal, Firewall & Core Repair
wp-admin-protect
Protect your WordPress. The ultimate lightweight security suite. Block brute-force attacks, auto-repair infected core files, hide your login URL, set …
Atlant Security
atlant-security
Enterprise-grade WordPress security: WAF, brute force protection, malware scanner, 2FA, honeypots, AI crawler control, and post-breach recovery.
Dotsquares Custom Login URL & Security Suite
custom-login-url-login-designer
Change your WordPress login URL, design the login page, and enhance your site's security with built-in protection tools.
FreelanceBo Sentra Control
freelancebo-sentra-control
Security agent connecting to FreelanceBo Sentra Control console for WAF, malware scanning, brute force protection, and vulnerability scanning.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Anti-Malware Security and Brute-Force Firewall Developer Profile
9 plugins · 101K total installs
How We Detect Anti-Malware Security and Brute-Force Firewall
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.