Advanced ads Management by Inazo Security & Risk Analysis

wordpress.org/plugins/inazo-advanced-ads-management

This plugin is an ads manager, that allow you to add ads with widget on your website.

10 active installs v1.5 PHP + WP 4.5.1+ Updated Dec 15, 2017
adspubpublicitepublicitywidget
85
A · Safe
CVEs total1
Unpatched0
Last CVESep 6, 2016
Download
Safety Verdict

Is Advanced ads Management by Inazo Safe to Use in 2026?

Generally Safe

Score 85/100

Advanced ads Management by Inazo has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 6, 2016Updated 8yr ago
Risk Assessment

The "inazo-advanced-ads-management" plugin v1.5 presents a mixed security posture. While it has a low total attack surface and no recorded unpatched vulnerabilities, several concerning patterns emerge from the static analysis. A significant risk lies with its single unprotected AJAX handler, which is a direct entry point for attackers. The presence of the `create_function` dangerous function is another red flag, as it can be exploited for code execution if not handled with extreme care, although no critical taint flows were found.

The plugin's output escaping is a notable weakness, with only 19% of outputs being properly escaped. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities. While the vulnerability history shows only a medium severity CVE from 2016, the lack of proper output escaping and the unprotected AJAX handler create a fertile ground for potential new XSS attacks, even if existing vulnerabilities are patched. The limited number of capability checks also raises concerns about potential privilege escalation if an attacker can bypass authorization.

In conclusion, the plugin has a small attack surface and no currently unpatched CVEs, which are positive aspects. However, the unprotected AJAX handler, poor output escaping practices, and the use of a dangerous function (`create_function`) introduce significant security risks that warrant immediate attention. The historical XSS vulnerability further underscores the importance of addressing the output escaping issues.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped outputs
  • Use of dangerous function 'create_function'
  • Low number of capability checks
  • Known medium severity vulnerability (historical)
Vulnerabilities
1

Advanced ads Management by Inazo Security Vulnerabilities

CVEs by Year

1 CVE in 2016
2016
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-7bccc409-e16f-4c32-ad3b-743defd7200f-inazo-advanced-ads-managementmedium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Inazo Advanced Ads Management < 1.4 - Authenticated Stored Cross-Site Scripting

Sep 6, 2016 Patched in 1.4 (2695d)
Code Analysis
Analyzed Mar 17, 2026

Advanced ads Management by Inazo Code Analysis

Dangerous Functions
1
Raw SQL Queries
2
6 prepared
Unescaped Output
55
13 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("inazo_widget_adds_manager");inazo.wp.adv.ads.management.php:53

SQL Query Safety

75% prepared8 total queries

Output Escaping

19% escaped68 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
ajaxAddCallback (inazo.wp.adv.ads.management.php:158)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Advanced ads Management by Inazo Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_inazo_wp_adds_manager_ajax_add_callbackinazo.wp.adv.ads.management.php:43
WordPress Hooks 6
actionadmin_menuinazo.wp.adv.ads.management.php:41
actionadmin_enqueue_scriptsinazo.wp.adv.ads.management.php:42
actionwp_enqueue_scriptsinazo.wp.adv.ads.management.php:44
actionplugins_loadedinazo.wp.adv.ads.management.php:48
actionwidgets_initinazo.wp.adv.ads.management.php:53
actionadmin_print_stylesinazo.wp.adv.ads.management.php:270
Maintenance & Trust

Advanced ads Management by Inazo Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 15, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Advanced ads Management by Inazo Developer Profile

inazo

3 plugins · 4K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
2695 days
View full developer profile
Detection Fingerprints

How We Detect Advanced ads Management by Inazo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/inazo-advanced-ads-management/css/jquery-ui.css/wp-content/plugins/inazo-advanced-ads-management/js/admin_add.js
Script Paths
/wp-content/plugins/inazo-advanced-ads-management/js/admin_add.js
Version Parameters
inazo-adds-manager-scriptinazo-adv-ads-manager

HTML / DOM Fingerprints

HTML Comments
<!-- @todo : faire une configuration CSS ? --><!-- * * Pour des raisons de sécurité aucun code ne doit être placé au dessus de cette ligne --><!-- * * Create the install of the plugin --><!-- * @todo to develop when i'll create an update -->+10 more
Data Attributes
token_csrf_action_edittoken_csrf_action_add
JS Globals
ajax_object
FAQ

Frequently Asked Questions about Advanced ads Management by Inazo