
GrabWP Tenancy Security & Risk Analysis
wordpress.org/plugins/grabwp-tenancyMulti-tenant WordPress with shared MySQL, domain and path routing, and isolated uploads.
Is GrabWP Tenancy Safe to Use in 2026?
Generally Safe
Score 100/100GrabWP Tenancy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The grabwp-tenancy v1.0.9 plugin exhibits a generally good security posture with several strengths, notably 100% proper output escaping and the use of prepared statements for all SQL queries. The absence of any known CVEs, critical or high severity vulnerabilities in its history, and no bundled libraries also contribute positively to its security profile. However, there are clear areas for concern. The presence of two AJAX handlers without authentication checks represents a significant attack surface that could be exploited. Furthermore, a single flow identified with unsanitized paths and rated as high severity taint analysis is a critical red flag. The use of the `unserialize` function, while not inherently vulnerable on its own, becomes dangerous when coupled with unsanitized input, potentially leading to deserialization vulnerabilities. The `set_time_limit` function, while not directly a security risk, can sometimes be indicative of performance issues or attempts to bypass execution limits, which warrants a minor degree of caution. Overall, while the plugin demonstrates good practices in many areas, the identified unprotected entry points and the high-severity taint flow require immediate attention to mitigate potential security risks.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow with unsanitized path
- Use of 'unserialize' function
GrabWP Tenancy Security Vulnerabilities
GrabWP Tenancy Release Timeline
GrabWP Tenancy Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
GrabWP Tenancy Attack Surface
AJAX Handlers 8
WordPress Hooks 24
Maintenance & Trust
GrabWP Tenancy Maintenance & Trust
Maintenance Signals
Community Trust
GrabWP Tenancy Alternatives
CM Multisite-Lite
cm-multisite-lite
Serve multiple front end websites with different content from a single WordPress installation.
Multisite Post Duplicator
multisite-post-duplicator
Duplicate/Copy/Clone any individual page, post or custom post type from one site on your multisite network to another.
Multi Site Plugins Add New
multi-site-plugins-add-new
Adds an "Add New" sub menu item to the Plugins menu of all sites inside of a network for network admins.
Multistore Multivendor
multistore-multivendor
This plugin allows you to show WooCommerce products on different domains or subdomains to make a multistore WooCommerce website.
Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform
ultimate-multisite
Ultimate Multisite turns your WordPress network into a WaaS platform with subscriptions, site provisioning, and domain mapping.
GrabWP Tenancy Developer Profile
2 plugins · 40 total installs
How We Detect GrabWP Tenancy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/grabwp-tenancy/assets/css/admin-style.css/wp-content/plugins/grabwp-tenancy/assets/css/tenant-admin-style.css/wp-content/plugins/grabwp-tenancy/assets/js/tenant-admin.js/wp-content/plugins/grabwp-tenancy/assets/js/grabwp-tenancy.js/wp-content/plugins/grabwp-tenancy/assets/js/tenant-admin.js/wp-content/plugins/grabwp-tenancy/assets/js/grabwp-tenancy.jsgrabwp-tenancy/assets/css/admin-style.css?ver=grabwp-tenancy/assets/css/tenant-admin-style.css?ver=grabwp-tenancy/assets/js/tenant-admin.js?ver=grabwp-tenancy/assets/js/grabwp-tenancy.js?ver=HTML / DOM Fingerprints
<!-- GrabWP Tenancy Main Site Initialization --><!-- GrabWP Tenancy Tenant Site Initialization -->data-grabwp-tenancy-tenant-idgrabwpTenancySettings