
History Log by click5 Security & Risk Analysis
wordpress.org/plugins/history-log-by-click5Best WordPress plugin to track user activity and log changes on your website.
Is History Log by click5 Safe to Use in 2026?
High Risk
Score 38/100History Log by click5 carries significant security risk with 3 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The "history-log-by-click5" plugin v1.0.13 presents a significant security risk primarily due to its substantial unprotected attack surface. With 25 unprotected entry points, including 23 AJAX handlers and 2 REST API routes lacking permission callbacks, this plugin is highly vulnerable to unauthorized access and manipulation. While the code exhibits good practices in other areas like SQL prepared statements (97%) and output escaping (96%), these strengths are overshadowed by the critical flaw of exposing numerous functionalities without proper authentication or authorization checks. The taint analysis also indicates a concerning flow with an unsanitized path, which, combined with the unprotected entry points, heightens the risk of code injection vulnerabilities.
The plugin's vulnerability history, with 3 known CVEs and 2 currently unpatched (1 high, 2 medium), strongly suggests a recurring pattern of security weaknesses, particularly concerning Cross-Site Scripting (XSS) and SQL Injection. The recent vulnerability in May 2025 further emphasizes the ongoing need for diligent security patching. In conclusion, while the plugin demonstrates some positive coding practices, the extensive unprotected attack surface and a history of exploitable vulnerabilities create a precarious security posture. Immediate attention is required to address the authentication and authorization gaps to mitigate the risk of compromise.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- Unpatched CVE (High Severity)
- Unpatched CVE (Medium Severity)
- Unpatched CVE (Medium Severity)
- Flow with unsanitized paths
- No capability checks
History Log by click5 Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
History Log by click5 <= 1.0.13 - Authenticated (Subscriber+) Stored Cross-Site Scripting
History Log by click5 <= 1.0.13 - Unauthenticated SQL Injection
History Log by click5 <= 1.0.12 - Authenticated(Administrator+) Time-Based Blind SQL Injection
History Log by click5 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
History Log by click5 Attack Surface
AJAX Handlers 23
REST API Routes 2
WordPress Hooks 113
Scheduled Events 2
Maintenance & Trust
History Log by click5 Maintenance & Trust
Maintenance Signals
Community Trust
History Log by click5 Alternatives
NextCellent Simple History
ngg-simple-history
Add Simple History integration for NextCellent.
Simple History – Track, Log, and Audit WordPress Changes
simple-history
Track changes and user activities on your WordPress site. See who created a page, uploaded an attachment, and more, for a complete audit trail.
WP Activity Log
wp-security-audit-log
The #1 user-rated activity log plugin for event logging, activity monitoring and change tracking.
Adminify Activity Logs
adminify-activity-logs
Track WordPress dashboard activities with this free plugin. Monitor user actions, filter by time, role for complete site security and accountability
Ambiscale Activity Manager
ambiscale-activity-manager
Monitor your website by logging all activities - from user behavior to system-level changes - giving you complete visibility directly from dashboard.
History Log by click5 Developer Profile
6 plugins · 7K total installs
How We Detect History Log by click5
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/history-log-by-click5/css/style.css/wp-content/plugins/history-log-by-click5/js/custom.js/wp-content/plugins/history-log-by-click5/js/custom.jshistory-log-by-click5/css/style.css?ver=history-log-by-click5/js/custom.js?ver=HTML / DOM Fingerprints
click5_history_log_tabledata-plugin-name="history-log-by-click5"click5_history_log_vars