Module Control for Jetpack Security & Risk Analysis

wordpress.org/plugins/jetpack-module-control

Your Jetpack, Controlled.

1K active installs v1.7.2 PHP + WP 4.6+ Updated Jun 25, 2025
blacklist-jetpack-modulesjetpackjetpack-lightslim-jetpackunplug-jetpack
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Module Control for Jetpack Safe to Use in 2026?

Generally Safe

Score 100/100

Module Control for Jetpack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "jetpack-module-control" plugin v1.7.2 exhibits a strong security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks, indicating a well-designed attack surface. The absence of dangerous functions, file operations, external HTTP requests, and raw SQL queries further reinforces this positive assessment. The plugin also demonstrates good practices by utilizing prepared statements for any SQL queries, though the total number of queries is zero.

However, a significant concern arises from the low rate of proper output escaping (14%). This suggests that data displayed by the plugin may not be sufficiently sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if any user-supplied data is rendered without adequate escaping. The lack of nonce checks and capability checks, combined with the low output escaping rate, points to potential areas where an attacker could exploit the plugin. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, the absence of historical vulnerabilities, coupled with the identified output escaping issue, might suggest that either the plugin has not been extensively tested for XSS or the identified issue has not yet been exploited or discovered.

In conclusion, while the plugin has a minimal attack surface and avoids common dangerous practices, the critical weakness in output escaping presents a tangible risk. The lack of historical vulnerabilities should not lead to complacency, especially given the identified code signals. Addressing the output escaping mechanism is paramount to improving its overall security.

Key Concerns

  • Low rate of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Module Control for Jetpack Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Module Control for Jetpack Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

14% escaped7 total outputs
Attack Surface

Module Control for Jetpack Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterjetpack_get_default_modulesjetpack-module-control.php:47
filterjetpack_offline_modejetpack-module-control.php:48
filterjetpack_get_available_modulesjetpack-module-control.php:49
actionadmin_initjetpack-module-control.php:51
actionadmin_menujetpack-module-control.php:52
filterwp_default_autoload_valuejetpack-module-control.php:53
Maintenance & Trust

Module Control for Jetpack Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 25, 2025
PHP min version
Downloads51K

Community Trust

Rating96/100
Number of ratings11
Active installs1K
Developer Profile

Module Control for Jetpack Developer Profile

Rolf Allard van Hagen

8 plugins · 111K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
293 days
View full developer profile
Detection Fingerprints

How We Detect Module Control for Jetpack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jetpack-module-control/inc/css/jetpack-module-control.css/wp-content/plugins/jetpack-module-control/inc/js/jetpack-module-control.js
Script Paths
/wp-content/plugins/jetpack-module-control/inc/js/jetpack-module-control.js
Version Parameters
jetpack-module-control/inc/css/jetpack-module-control.css?ver=jetpack-module-control/inc/js/jetpack-module-control.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-jetpack-mc-setting
FAQ

Frequently Asked Questions about Module Control for Jetpack