IronPhantom Antifraud Security & Risk Analysis

wordpress.org/plugins/ironphantom-antifraud

IronPhantom Antifraud brings real-time fraud intelligence to WooCommerce.

0 active installs v1.0.12 PHP 7.4+ WP 6.1+ Updated Mar 8, 2026
antifraudcheckoutfraud-detectionsecuritywoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is IronPhantom Antifraud Safe to Use in 2026?

Generally Safe

Score 100/100

IronPhantom Antifraud has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 26d ago
Risk Assessment

The "ironphantom-antifraud" plugin v1.0.12 exhibits a generally good security posture, with significant strengths in its handling of SQL queries and output escaping. The plugin effectively utilizes prepared statements for all its SQL queries, which is a critical practice for preventing SQL injection vulnerabilities. Furthermore, a high percentage of its output is properly escaped, mitigating the risk of cross-site scripting (XSS) attacks. The absence of known CVEs and a clean vulnerability history further contribute to its positive security profile, suggesting a well-maintained and secure codebase.

Key Concerns

  • AJAX handlers without authentication checks
Vulnerabilities
None known

IronPhantom Antifraud Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

IronPhantom Antifraud Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
10
44 escaped
Nonce Checks
17
Capability Checks
16
File Operations
0
External Requests
17
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

81% escaped54 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
iron_phn_verify_api_key (init\modal-files.php:62)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

IronPhantom Antifraud Attack Surface

Entry Points21
Unprotected3

AJAX Handlers 21

authwp_ajax_ironphantom_admin_toast_pinginc\admin_toast_ping.php:92
authwp_ajax_ironphantom_cerebrusx_statusinc\ironphantom-cerebrusx.php:20
authwp_ajax_ironphantom_cerebrusx_behaviorinc\ironphantom-cerebrusx.php:21
authwp_ajax_ironphantom_system_checkinc\system-check.php:15
authwp_ajax_ironphantom_check_high_riskinc\toast-admin-notification.php:31
authwp_ajax_request_api_keyinit\modal-files.php:11
noprivwp_ajax_request_api_keyinit\modal-files.php:12
authwp_ajax_verify_api_keyinit\modal-files.php:59
noprivwp_ajax_verify_api_keyinit\modal-files.php:60
authwp_ajax_iron_phn_save_settingsinit\modal-files.php:110
authwp_ajax_ironphantom_on_activation_save_settingsinit\modal-files.php:111
authwp_ajax_ironphantom_on_activation_skip_setupironphantom-antifraud.php:537
authwp_ajax_ironphantom_resume_installationironphantom-antifraud.php:596
authwp_ajax_ironphantom_get_transactionsironphantom-antifraud.php:759
noprivwp_ajax_ironphantom_get_transactionsironphantom-antifraud.php:760
authwp_ajax_ironphantom_get_alerts_liveironphantom-antifraud.php:887
authwp_ajax_ironphantom_get_system_statusironphantom-antifraud.php:939
authwp_ajax_ironphantom_get_cerebrusx_statusironphantom-antifraud.php:990
authwp_ajax_ironphantom_get_suspicious_activityironphantom-antifraud.php:1082
authwp_ajax_ironphantom_dismiss_transactionironphantom-antifraud.php:1153
authwp_ajax_ironphantom_get_cerebrusx_systemironphantom-antifraud.php:1235
WordPress Hooks 24
actionadmin_enqueue_scriptsinc\admin_toast_ping.php:16
actionadmin_menuinc\system-check.php:13
actionadmin_enqueue_scriptsinc\system-check.php:14
actionadmin_noticesinc\system-check.php:25
actionadmin_enqueue_scriptsinc\toast-admin-notification.php:30
actionwp_footerinc\toast_universal.php:215
actiontemplate_redirectinc\toast_universal.php:218
actionplugins_loadedironphantom-antifraud.php:19
actionadmin_initironphantom-antifraud.php:37
actioninitironphantom-antifraud.php:193
filterwoocommerce_get_settings_generalironphantom-antifraud.php:197
actionwoocommerce_update_options_generalironphantom-antifraud.php:261
actionwoocommerce_checkout_order_processedironphantom-antifraud.php:372
actionwoocommerce_thankyouironphantom-antifraud.php:420
actionwoocommerce_payment_completeironphantom-antifraud.php:423
actionwoocommerce_order_status_changedironphantom-antifraud.php:426
actionwp_loginironphantom-antifraud.php:434
actionwp_enqueue_scriptsironphantom-antifraud.php:481
actionadmin_enqueue_scriptsironphantom-antifraud.php:514
actionadmin_footerironphantom-antifraud.php:516
actionadmin_menuironphantom-antifraud.php:562
actionadmin_enqueue_scriptsironphantom-antifraud.php:617
actionadmin_enqueue_scriptsironphantom-antifraud.php:644
actionadmin_enqueue_scriptsironphantom-antifraud.php:699
Maintenance & Trust

IronPhantom Antifraud Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 8, 2026
PHP min version7.4
Downloads541

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

IronPhantom Antifraud Developer Profile

Fabrizio D.

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IronPhantom Antifraud

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ironphantom-antifraud/assets/js/antifraud-backend.js/wp-content/plugins/ironphantom-antifraud/assets/css/antifraud-backend.css
Script Paths
/wp-content/plugins/ironphantom-antifraud/assets/js/antifraud-backend.js/wp-content/plugins/ironphantom-antifraud/assets/js/antifraud-frontend.js
Version Parameters
ironphantom-antifraud/assets/js/antifraud-backend.js?ver=ironphantom-antifraud/assets/css/antifraud-backend.css?ver=ironphantom-antifraud/assets/js/antifraud-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
ironphantom-activation-modalironphantom-login-modal
HTML Comments
🔹 Plugin IronPhantom caricato (init).🔥 IronPhantom: verifica stato configurazione✅ IronPhantom: configurazione valida.❌ IronPhantom: API Key mancante. Mostro wizard...+4 more
Data Attributes
data-ironphantom-api-keydata-ironphantom-url
JS Globals
window.ironphantom_settings
FAQ

Frequently Asked Questions about IronPhantom Antifraud