
HTTP Requests Manager Security & Risk Analysis
wordpress.org/plugins/http-requests-managerLimit, Debug, Optimize WP_HTTP requests. Limit by request count, page load time, reduce timeout for each request. Speed up login and admin pages.
Is HTTP Requests Manager Safe to Use in 2026?
Generally Safe
Score 100/100HTTP Requests Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'http-requests-manager' plugin, version 1.3.10, presents a significant security risk due to its unprotected AJAX handlers. All 8 identified AJAX entry points lack authentication checks, meaning any unauthenticated user could potentially trigger these functions. While the plugin doesn't exhibit known vulnerabilities or critical code signals like dangerous functions or unsanitized taint flows, the sheer number of unprotected entry points creates a substantial attack surface. The limited output escaping also raises concerns about potential cross-site scripting (XSS) vulnerabilities, although the specific impact is unclear without deeper code review. The absence of recorded vulnerabilities historically is a positive sign, suggesting the developers might be attentive to security. However, this should not overshadow the immediate risks posed by the unprotected AJAX handlers. The plugin has a moderate security posture, with notable weaknesses in access control for its AJAX endpoints that demand immediate attention.
Key Concerns
- 8 AJAX handlers without auth checks
- Only 32% of outputs properly escaped
HTTP Requests Manager Security Vulnerabilities
HTTP Requests Manager Code Analysis
SQL Query Safety
Output Escaping
HTTP Requests Manager Attack Surface
AJAX Handlers 8
WordPress Hooks 26
Scheduled Events 1
Maintenance & Trust
HTTP Requests Manager Maintenance & Trust
Maintenance Signals
Community Trust
HTTP Requests Manager Alternatives
Robin Image Optimizer – Unlimited Image Optimization & WebP Converter
robin-image-optimizer
Unlimited automatic image optimization for WordPress. Compress images, convert to WebP, and improve site speed without losing image quality.
WPS Limit Login
wps-limit-login
WPS Limit login limit connection attempts by IP address
Titan Anti-spam & Security
anti-spam
Block spam comments, defend against login attempts, and strengthen site security with anti-spam, brute-force protection, and two-factor authentication …
Inactive Logout
inactive-logout
Automatically logout idle user sessions, with logout redirections and concurrent limit logins all in one place.
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress
fluent-security
Enhance the Security and User Experience of Your Site with Login/Signup Security, Two-Factor Email Authentication, Social Logins and more...
HTTP Requests Manager Developer Profile
2 plugins · 2K total installs
How We Detect HTTP Requests Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/http-requests-manager/assets/css/http-requests-manager.css/wp-content/plugins/http-requests-manager/assets/js/http-requests-manager.js/wp-content/plugins/http-requests-manager/assets/js/app.js/wp-content/plugins/http-requests-manager/assets/js/http-requests-manager.js/wp-content/plugins/http-requests-manager/assets/js/app.jshttp-requests-manager/assets/css/http-requests-manager.css?ver=http-requests-manager/assets/js/http-requests-manager.js?ver=http-requests-manager/assets/js/app.js?ver=HTML / DOM Fingerprints
http-requests-manager-wrapvphrm-custom-rule-itemTODO:NOT POSSIBLE:conflict test.safemode URL parameter to disable loggingdata-vphrm-iddata-vphrm-titledata-vphrm-rule-typedata-vphrm-rule-valueVPHRM_AJAX_URLVPHRM_AJAX_NONCEVPHRM_CURRENT_PAGEVPHRM_PLUGIN_VERSIONvphrm_localize/wp-json/http-requests-manager/v1/rules/wp-json/http-requests-manager/v1/logs/wp-json/http-requests-manager/v1/settings