IP Blacklist for Cloudflare Security & Risk Analysis

wordpress.org/plugins/ip-blacklist-cloudflare

Blacklist IP addresses that attempt to login with a banned username through Cloudflare.

30 active installs v1.2.2 PHP 8.1+ WP + Updated Feb 17, 2026
loginpasswordpasswordsprofilesecurity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is IP Blacklist for Cloudflare Safe to Use in 2026?

Generally Safe

Score 100/100

IP Blacklist for Cloudflare has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "ip-blacklist-cloudflare" plugin v1.2.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output. There are no known vulnerabilities in its history, nor are there any reported critical or high-severity taint analysis findings, suggesting a generally secure coding approach for sensitive operations.

However, a significant concern arises from the plugin's attack surface. It exposes three AJAX handlers, and alarmingly, all three lack any authentication checks. This means any unauthenticated user could potentially trigger these AJAX actions, which could lead to unintended consequences or be leveraged as a stepping stone for further attacks. While the static analysis did not reveal dangerous functions or file operations, the absence of authentication on such critical entry points is a major security weakness that needs immediate attention.

In conclusion, while the plugin avoids common pitfalls like unescaped output and raw SQL, the unauthenticated AJAX endpoints represent a substantial risk. The lack of vulnerability history is a positive indicator, but it does not negate the immediate threat posed by the exposed AJAX handlers. Addressing these unauthenticated entry points should be the highest priority.

Key Concerns

  • Unprotected AJAX handlers
Vulnerabilities
None known

IP Blacklist for Cloudflare Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

IP Blacklist for Cloudflare Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
113 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped113 total outputs
Attack Surface
3 unprotected

IP Blacklist for Cloudflare Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_cfip_unblacklist_ipclasses\Plugin.php:68
authwp_ajax_cfip_clearlogclasses\Plugin.php:69
authwp_ajax_cfip_loadlogclasses\Plugin.php:70
WordPress Hooks 6
actionadmin_enqueue_scriptsclasses\Plugin.php:62
actionwp_authenticateclasses\Plugin.php:65
actionadmin_menuclasses\Plugin.php:73
actionadmin_menuclasses\Plugin.php:74
actionadmin_noticesclasses\ReviewNotice.php:33
actionadmin_initclasses\ReviewNotice.php:34
Maintenance & Trust

IP Blacklist for Cloudflare Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 17, 2026
PHP min version8.1
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

IP Blacklist for Cloudflare Developer Profile

Matt Miller

7 plugins · 11K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
28 days
View full developer profile
Detection Fingerprints

How We Detect IP Blacklist for Cloudflare

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ip-blacklist-cloudflare/assets/css/admin.css/wp-content/plugins/ip-blacklist-cloudflare/assets/js/admin.js
Script Paths
/wp-content/plugins/cloudflare/stylesheets/cf.core.css/wp-content/plugins/cloudflare/stylesheets/components.css/wp-content/plugins/cloudflare/stylesheets/hacks.css
Version Parameters
ip-blacklist-cloudflare/assets/js/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
cfip_i18n
FAQ

Frequently Asked Questions about IP Blacklist for Cloudflare