
InfiniteWP Client Security & Risk Analysis
wordpress.org/plugins/iwp-clientInstall this plugin on unlimited sites and manage them all from a central dashboard. This plugin communicates with your InfiniteWP Admin Panel.
Is InfiniteWP Client Safe to Use in 2026?
Generally Safe
Score 90/100InfiniteWP Client has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The iwp-client v1.13.5 plugin presents a concerning security posture, despite having no currently unpatched CVEs. The static analysis reveals significant weaknesses, particularly the complete absence of nonce checks and a very low percentage of properly escaped output. The high number of "dangerous functions" like `unserialize`, `popen`, `exec`, and `system` combined with 8 out of 9 analyzed taint flows having unsanitized paths, 5 of which are rated as high severity, strongly suggests a high risk of remote code execution and path traversal vulnerabilities. The plugin's history of 7 CVEs, including 4 critical ones, further amplifies these concerns, indicating a recurring pattern of severe security flaws. While the presence of Guzzle as a bundled library is a positive sign for potential managed dependencies, it does not outweigh the critical issues found in core plugin logic.
Key Concerns
- No nonce checks on entry points
- High number of dangerous functions
- Low output escaping percentage
- High severity taint flows (unsanitized paths)
- Multiple critical CVEs in history
- High number of file operations
- Bundled library (Guzzle) not checked for vulns
InfiniteWP Client Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
InfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File Reading
InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure
InfiniteWP Client <= 1.11.1 - Authenticated (Subscriber+) Sensitive Information Exposure
InfiniteWP Client <= 1.9.4.4 - Authentication Bypass
InfiniteWP Client <= 1.6.0 - Unauthenticated PHP Object Injection
InfiniteWP Client <= 1.3.7 - Privilege Escalation
InfiniteWP Client <= 1.3.7 - PHP Object Injection
InfiniteWP Client Release Timeline
InfiniteWP Client Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
InfiniteWP Client Attack Surface
WordPress Hooks 90
Scheduled Events 7
Maintenance & Trust
InfiniteWP Client Maintenance & Trust
Maintenance Signals
Community Trust
InfiniteWP Client Alternatives
Solid Central – Site Management, Backups, Security, and Reporting
ithemes-sync
Manage multiple WordPress sites from one dashboard.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
Modular DS: Monitor, update, and backup multiple websites
modular-connector
Manage all your WordPress sites from one place. Automate updates, backups, uptime monitoring, security, maintenance reports, and more.
InfiniteWP Client Developer Profile
8 plugins · 224K total installs
How We Detect InfiniteWP Client
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iwp-client/iwp_mmb_utils.css/wp-content/plugins/iwp-client/css/custom_admin.css/wp-content/plugins/iwp-client/js/iwp_mmb.js/wp-content/plugins/iwp-client/js/iwp_mmb_dashboard.js/wp-content/plugins/iwp-client/js/iwp_mmb_stats.js/wp-content/plugins/iwp-client/js/iwp_mmb_backup.js/wp-content/plugins/iwp-client/js/iwp_mmb_maintenance.js/wp-content/plugins/iwp-client/js/iwp_mmb_users.js+14 more/wp-content/plugins/iwp-client/js/iwp_mmb.js/wp-content/plugins/iwp-client/js/iwp_mmb_dashboard.js/wp-content/plugins/iwp-client/js/iwp_mmb_stats.js/wp-content/plugins/iwp-client/js/iwp_mmb_backup.js/wp-content/plugins/iwp-client/js/iwp_mmb_maintenance.js/wp-content/plugins/iwp-client/js/iwp_mmb_users.js+14 moreiwp-client/iwp_mmb_utils.css?ver=iwp-client/css/custom_admin.css?ver=iwp-client/js/iwp_mmb.js?ver=iwp-client/js/iwp_mmb_dashboard.js?ver=iwp-client/js/iwp_mmb_stats.js?ver=iwp-client/js/iwp_mmb_backup.js?ver=iwp-client/js/iwp_mmb_maintenance.js?ver=iwp-client/js/iwp_mmb_users.js?ver=iwp-client/js/iwp_mmb_plugins.js?ver=iwp-client/js/iwp_mmb_themes.js?ver=iwp-client/js/iwp_mmb_comments.js?ver=iwp-client/js/iwp_mmb_posts.js?ver=iwp-client/js/iwp_mmb_pages.js?ver=iwp-client/js/iwp_mmb_links.js?ver=iwp-client/js/iwp_mmb_install_addon.js?ver=iwp-client/js/iwp_mmb_optimizer.js?ver=iwp-client/js/iwp_mmb_security.js?ver=iwp-client/js/iwp_mmb_cache.js?ver=iwp-client/js/iwp_mmb_client_brand.js?ver=iwp-client/js/iwp_mmb_broken_links.js?ver=iwp-client/js/iwp_mmb_updates.js?ver=iwp-client/js/iwp_mmb_restore.js?ver=HTML / DOM Fingerprints
iwp_mmb_dashboard_widgetiwp_mmb_custom_cssiwp_mmb_menu_cssiwp_mmb_main_wrapperiwp_mmb_plugin_update_btniwp_mmb_theme_update_btniwp_mmb_maintenance_mode_activeiwp_mmb_message_success+12 moreCopyright (c) 2012 Revmakxwww.revmakx.comCopyright (c) 2011 Prelovac Mediawww.prelovac.com+4 moredata-iwp-noncedata-iwp-actiondata-iwp-blog-iddata-iwp-item-iddata-iwp-plugin-slugdata-iwp-theme-slug+1 moreiwp_mmb_coreiwp_mmb_vars/wp-json/iwp-client/v1/actions