
InfiniteWP Client Security & Risk Analysis
wordpress.org/plugins/iwp-clientInstall this plugin on unlimited sites and manage them all from a central dashboard. This plugin communicates with your InfiniteWP Admin Panel.
Is InfiniteWP Client Safe to Use in 2026?
Generally Safe
Score 90/100InfiniteWP Client has a strong security track record. Known vulnerabilities have been patched promptly.
The iwp-client v1.13.5 plugin presents a concerning security posture, despite having no currently unpatched CVEs. The static analysis reveals significant weaknesses, particularly the complete absence of nonce checks and a very low percentage of properly escaped output. The high number of "dangerous functions" like `unserialize`, `popen`, `exec`, and `system` combined with 8 out of 9 analyzed taint flows having unsanitized paths, 5 of which are rated as high severity, strongly suggests a high risk of remote code execution and path traversal vulnerabilities. The plugin's history of 7 CVEs, including 4 critical ones, further amplifies these concerns, indicating a recurring pattern of severe security flaws. While the presence of Guzzle as a bundled library is a positive sign for potential managed dependencies, it does not outweigh the critical issues found in core plugin logic.
Key Concerns
- No nonce checks on entry points
- High number of dangerous functions
- Low output escaping percentage
- High severity taint flows (unsanitized paths)
- Multiple critical CVEs in history
- High number of file operations
- Bundled library (Guzzle) not checked for vulns
InfiniteWP Client Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
InfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File Reading
InfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information Exposure
InfiniteWP Client <= 1.11.1 - Authenticated (Subscriber+) Sensitive Information Exposure
InfiniteWP Client <= 1.9.4.4 - Authentication Bypass
InfiniteWP Client <= 1.6.0 - Unauthenticated PHP Object Injection
InfiniteWP Client <= 1.3.7 - Privilege Escalation
InfiniteWP Client <= 1.3.7 - PHP Object Injection
InfiniteWP Client Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
InfiniteWP Client Attack Surface
WordPress Hooks 90
Scheduled Events 7
Maintenance & Trust
InfiniteWP Client Maintenance & Trust
Maintenance Signals
Community Trust
InfiniteWP Client Alternatives
Solid Central – Site Management, Backups, Security, and Reporting
ithemes-sync
Manage multiple WordPress sites from one dashboard.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
Modular DS: Monitor, update, and backup multiple websites
modular-connector
Manage all your WordPress sites from one place. Automate updates, backups, uptime monitoring, security, maintenance reports, and more.
InfiniteWP Client Developer Profile
6 plugins · 224K total installs
How We Detect InfiniteWP Client
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/iwp-client/iwp_mmb_utils.css/wp-content/plugins/iwp-client/css/custom_admin.css/wp-content/plugins/iwp-client/js/iwp_mmb.js/wp-content/plugins/iwp-client/js/iwp_mmb_dashboard.js/wp-content/plugins/iwp-client/js/iwp_mmb_stats.js/wp-content/plugins/iwp-client/js/iwp_mmb_backup.js/wp-content/plugins/iwp-client/js/iwp_mmb_maintenance.js/wp-content/plugins/iwp-client/js/iwp_mmb_users.js+14 more/wp-content/plugins/iwp-client/js/iwp_mmb.js/wp-content/plugins/iwp-client/js/iwp_mmb_dashboard.js/wp-content/plugins/iwp-client/js/iwp_mmb_stats.js/wp-content/plugins/iwp-client/js/iwp_mmb_backup.js/wp-content/plugins/iwp-client/js/iwp_mmb_maintenance.js/wp-content/plugins/iwp-client/js/iwp_mmb_users.js+14 moreiwp-client/iwp_mmb_utils.css?ver=iwp-client/css/custom_admin.css?ver=iwp-client/js/iwp_mmb.js?ver=iwp-client/js/iwp_mmb_dashboard.js?ver=iwp-client/js/iwp_mmb_stats.js?ver=iwp-client/js/iwp_mmb_backup.js?ver=iwp-client/js/iwp_mmb_maintenance.js?ver=iwp-client/js/iwp_mmb_users.js?ver=iwp-client/js/iwp_mmb_plugins.js?ver=iwp-client/js/iwp_mmb_themes.js?ver=iwp-client/js/iwp_mmb_comments.js?ver=iwp-client/js/iwp_mmb_posts.js?ver=iwp-client/js/iwp_mmb_pages.js?ver=iwp-client/js/iwp_mmb_links.js?ver=iwp-client/js/iwp_mmb_install_addon.js?ver=iwp-client/js/iwp_mmb_optimizer.js?ver=iwp-client/js/iwp_mmb_security.js?ver=iwp-client/js/iwp_mmb_cache.js?ver=iwp-client/js/iwp_mmb_client_brand.js?ver=iwp-client/js/iwp_mmb_broken_links.js?ver=iwp-client/js/iwp_mmb_updates.js?ver=iwp-client/js/iwp_mmb_restore.js?ver=HTML / DOM Fingerprints
iwp_mmb_dashboard_widgetiwp_mmb_custom_cssiwp_mmb_menu_cssiwp_mmb_main_wrapperiwp_mmb_plugin_update_btniwp_mmb_theme_update_btniwp_mmb_maintenance_mode_activeiwp_mmb_message_success+12 moreCopyright (c) 2012 Revmakxwww.revmakx.comCopyright (c) 2011 Prelovac Mediawww.prelovac.com+4 moredata-iwp-noncedata-iwp-actiondata-iwp-blog-iddata-iwp-item-iddata-iwp-plugin-slugdata-iwp-theme-slug+1 moreiwp_mmb_coreiwp_mmb_vars/wp-json/iwp-client/v1/actions