
Advanced ads Management by Inazo Security & Risk Analysis
wordpress.org/plugins/inazo-advanced-ads-managementThis plugin is an ads manager, that allow you to add ads with widget on your website.
Is Advanced ads Management by Inazo Safe to Use in 2026?
Generally Safe
Score 85/100Advanced ads Management by Inazo has a strong security track record. Known vulnerabilities have been patched promptly.
The "inazo-advanced-ads-management" plugin v1.5 presents a mixed security posture. While it has a low total attack surface and no recorded unpatched vulnerabilities, several concerning patterns emerge from the static analysis. A significant risk lies with its single unprotected AJAX handler, which is a direct entry point for attackers. The presence of the `create_function` dangerous function is another red flag, as it can be exploited for code execution if not handled with extreme care, although no critical taint flows were found.
The plugin's output escaping is a notable weakness, with only 19% of outputs being properly escaped. This significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities. While the vulnerability history shows only a medium severity CVE from 2016, the lack of proper output escaping and the unprotected AJAX handler create a fertile ground for potential new XSS attacks, even if existing vulnerabilities are patched. The limited number of capability checks also raises concerns about potential privilege escalation if an attacker can bypass authorization.
In conclusion, the plugin has a small attack surface and no currently unpatched CVEs, which are positive aspects. However, the unprotected AJAX handler, poor output escaping practices, and the use of a dangerous function (`create_function`) introduce significant security risks that warrant immediate attention. The historical XSS vulnerability further underscores the importance of addressing the output escaping issues.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped outputs
- Use of dangerous function 'create_function'
- Low number of capability checks
- Known medium severity vulnerability (historical)
Advanced ads Management by Inazo Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Inazo Advanced Ads Management < 1.4 - Authenticated Stored Cross-Site Scripting
Advanced ads Management by Inazo Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Advanced ads Management by Inazo Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Advanced ads Management by Inazo Maintenance & Trust
Maintenance Signals
Community Trust
Advanced ads Management by Inazo Alternatives
Fixed Widget and Sticky Elements for WordPress
q2w3-fixed-widget
More attention and a higher ad performance with fixed sticky widgets.
Meks Easy Ads Widget
meks-easy-ads-widget
Display unlimited number of ads inside your WordPress widget.
Ads.txt File Manager By Magicbid
ads-txt-by-magicbid
Easily manage ads.txt and app-ads.txt files from your WordPress dashboard with editing, backup, and restore options.
WP Calameo
wp-calameo
This plugin allows to embed Calaméo publications in blog posts. Copy the WordPress embed code and paste it into your post.
AdWords Conversion Tracking Code
adwords-conversion-tracking-code
Easiest way to add AdWords Conversion Tracking Code to your site.
Advanced ads Management by Inazo Developer Profile
3 plugins · 4K total installs
How We Detect Advanced ads Management by Inazo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inazo-advanced-ads-management/css/jquery-ui.css/wp-content/plugins/inazo-advanced-ads-management/js/admin_add.js/wp-content/plugins/inazo-advanced-ads-management/js/admin_add.jsinazo-adds-manager-scriptinazo-adv-ads-managerHTML / DOM Fingerprints
<!-- @todo : faire une configuration CSS ? --><!--
*
* Pour des raisons de sécurité aucun code ne doit être placé au dessus de cette ligne
--><!--
*
* Create the install of the plugin
--><!--
* @todo to develop when i'll create an update
-->+10 moretoken_csrf_action_edittoken_csrf_action_addajax_object