
HTTP Requests Manager Security & Risk Analysis
wordpress.org/plugins/http-requests-managerLimit, Debug, Optimize WP_HTTP requests. Limit by request count, page load time, reduce timeout for each request. Speed up login and admin pages.
Is HTTP Requests Manager Safe to Use in 2026?
Generally Safe
Score 100/100HTTP Requests Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'http-requests-manager' plugin, version 1.3.10, presents a significant security risk due to its unprotected AJAX handlers. All 8 identified AJAX entry points lack authentication checks, meaning any unauthenticated user could potentially trigger these functions. While the plugin doesn't exhibit known vulnerabilities or critical code signals like dangerous functions or unsanitized taint flows, the sheer number of unprotected entry points creates a substantial attack surface. The limited output escaping also raises concerns about potential cross-site scripting (XSS) vulnerabilities, although the specific impact is unclear without deeper code review. The absence of recorded vulnerabilities historically is a positive sign, suggesting the developers might be attentive to security. However, this should not overshadow the immediate risks posed by the unprotected AJAX handlers. The plugin has a moderate security posture, with notable weaknesses in access control for its AJAX endpoints that demand immediate attention.
Key Concerns
- 8 AJAX handlers without auth checks
- Only 32% of outputs properly escaped
HTTP Requests Manager Security Vulnerabilities
HTTP Requests Manager Release Timeline
HTTP Requests Manager Code Analysis
SQL Query Safety
Output Escaping
HTTP Requests Manager Attack Surface
AJAX Handlers 8
WordPress Hooks 26
Scheduled Events 1
Maintenance & Trust
HTTP Requests Manager Maintenance & Trust
Maintenance Signals
Community Trust
HTTP Requests Manager Alternatives
WPS Limit Login
wps-limit-login
WPS Limit login limit connection attempts by IP address
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress
fluent-security
Enhance the Security and User Experience of Your Site with Login/Signup Security, Two-Factor Email Authentication, Social Logins and more...
Inactive Logout
inactive-logout
Automatically logout idle user sessions, with logout redirections and concurrent limit logins all in one place.
WP Limit Login Attempts
wp-limit-login-attempts
Limit rate of login attempts and block IP temporarily. Brute force attack protection. GDPR compliant. Captcha enabled.
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages
freesoul-deactivate-plugins
Load plugins only where you need them. No bloat, no conflicts, more speed. Deactivate plugins where they don't add anything useful.
HTTP Requests Manager Developer Profile
2 plugins · 2K total installs
How We Detect HTTP Requests Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/http-requests-manager/assets/css/http-requests-manager.css/wp-content/plugins/http-requests-manager/assets/js/http-requests-manager.js/wp-content/plugins/http-requests-manager/assets/js/app.js/wp-content/plugins/http-requests-manager/assets/js/http-requests-manager.js/wp-content/plugins/http-requests-manager/assets/js/app.jshttp-requests-manager/assets/css/http-requests-manager.css?ver=http-requests-manager/assets/js/http-requests-manager.js?ver=http-requests-manager/assets/js/app.js?ver=HTML / DOM Fingerprints
http-requests-manager-wrapvphrm-custom-rule-itemTODO:NOT POSSIBLE:conflict test.safemode URL parameter to disable loggingdata-vphrm-iddata-vphrm-titledata-vphrm-rule-typedata-vphrm-rule-valueVPHRM_AJAX_URLVPHRM_AJAX_NONCEVPHRM_CURRENT_PAGEVPHRM_PLUGIN_VERSIONvphrm_localize/wp-json/http-requests-manager/v1/rules/wp-json/http-requests-manager/v1/logs/wp-json/http-requests-manager/v1/settings