
Solid Central – Site Management, Backups, Security, and Reporting Security & Risk Analysis
wordpress.org/plugins/ithemes-syncManage multiple WordPress sites from one dashboard.
Is Solid Central – Site Management, Backups, Security, and Reporting Safe to Use in 2026?
Generally Safe
Score 97/100Solid Central – Site Management, Backups, Security, and Reporting has a strong security track record. Known vulnerabilities have been patched promptly.
The iThemes Sync plugin v3.2.9 presents a mixed security posture. On the positive side, the static analysis indicates a limited attack surface, with no immediately unprotected entry points like AJAX handlers or REST API routes without proper checks. The plugin also demonstrates good practices in output escaping, with a high percentage of outputs being properly sanitized, and a reasonable number of capability checks in place. However, significant concerns arise from the presence of dangerous functions like `shell_exec`, `exec`, `system`, and `passthru`. These functions, if misused or exposed to untrusted input, can lead to severe command injection vulnerabilities.
The vulnerability history is also a cause for concern, with a total of 3 known CVEs, including one critical vulnerability. While there are currently no unpatched CVEs, the pattern of past vulnerabilities, including Cross-Site Scripting, CSRF, and Incorrect User Management, suggests potential recurring weaknesses in input validation and access control. The single taint flow with an unsanitized path, while not rated critical or high, warrants careful investigation, especially in conjunction with the dangerous functions identified. The relatively low percentage of SQL queries using prepared statements also indicates a potential for SQL injection vulnerabilities.
In conclusion, while iThemes Sync v3.2.9 has some strengths in its limited attack surface and output sanitization, the use of dangerous system execution functions and the history of critical and medium severity vulnerabilities, coupled with less than ideal SQL preparedness, necessitate caution. The plugin's historical track record and the presence of potent but risky functions point to a need for ongoing vigilance and timely updates.
Key Concerns
- Presence of dangerous system execution functions
- History of critical severity vulnerability
- SQL queries not fully using prepared statements
- Flows with unsanitized paths identified
- History of Cross-Site Scripting vulnerabilities
- History of Cross-Site Request Forgery vulnerabilities
- History of Incorrect User Management vulnerabilities
Solid Central – Site Management, Backups, Security, and Reporting Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Solid Central <= 3.0.0 - Stored Cross-Site Scripting via packages
iThemes Sync <= 2.1.13 - Cross-Site Request Forgery and Missing Authorization via 'hide_authenticate_notice'
iThemes Sync <= 2.0.17 - Authentication Bypass
Solid Central – Site Management, Backups, Security, and Reporting Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Solid Central – Site Management, Backups, Security, and Reporting Attack Surface
AJAX Handlers 1
WordPress Hooks 86
Scheduled Events 1
Maintenance & Trust
Solid Central – Site Management, Backups, Security, and Reporting Maintenance & Trust
Maintenance Signals
Community Trust
Solid Central – Site Management, Backups, Security, and Reporting Alternatives
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
InfiniteWP Client
iwp-client
Install this plugin on unlimited sites and manage them all from a central dashboard. This plugin communicates with your InfiniteWP Admin Panel.
Modular DS: Monitor, update, and backup multiple websites
modular-connector
Manage all your WordPress sites from one place. Automate updates, backups, uptime monitoring, security, maintenance reports, and more.
Solid Central – Site Management, Backups, Security, and Reporting Developer Profile
26 plugins · 3.1M total installs
How We Detect Solid Central – Site Management, Backups, Security, and Reporting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ithemes-sync/css/admin-notice.css/wp-content/plugins/ithemes-sync/js/admin-notice.js/wp-content/plugins/ithemes-sync/js/admin-notice.jsithemes-sync/css/admin-notice.css?ver=ithemes-sync/js/admin-notice.js?ver=HTML / DOM Fingerprints
ithemes-sync-noticeithemes-sync-notice-buttonithemes-sync-notice-hidedata-dismiss-nonceithemes_sync_notice