
Send Secrets By Kaboom Security & Risk Analysis
wordpress.org/plugins/kaboom-send-secretsThis plugin makes it possible to send secrets to your clients. You use the shortcode [stand_alone_send_secret], there will appear an input field to se …
Is Send Secrets By Kaboom Safe to Use in 2026?
Generally Safe
Score 100/100Send Secrets By Kaboom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'kaboom-send-secrets' plugin, version 1.0.4, exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. The plugin also demonstrates good practices with the presence of nonce and capability checks, and no external HTTP requests or file operations that could be exploited. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further contributes to its secure profile.
However, a significant concern lies within the handling of SQL queries. All four identified SQL queries are executed without prepared statements. This practice exposes the plugin to a substantial risk of SQL injection vulnerabilities, which could allow attackers to manipulate database queries, potentially leading to data theft, modification, or deletion. While the taint analysis did not reveal any unsanitized paths in the limited flows analyzed, the lack of prepared statements for all SQL operations is a critical oversight that needs immediate attention.
In conclusion, while the plugin benefits from a low attack surface and good security practices in most areas, the unmitigated risk of SQL injection due to the exclusive use of raw SQL queries is a major weakness. The strong vulnerability history is encouraging, but it should not lead to complacency, especially given the clear SQL handling issue.
Key Concerns
- Raw SQL queries without prepared statements
Send Secrets By Kaboom Security Vulnerabilities
Send Secrets By Kaboom Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Send Secrets By Kaboom Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Send Secrets By Kaboom Maintenance & Trust
Maintenance Signals
Community Trust
Send Secrets By Kaboom Alternatives
BBQ Firewall – Fast & Powerful Firewall Security
block-bad-queries
The fastest firewall plugin for WordPress. Protect against a wide range of threats with minimal performance impact.
Easy HTTPS Redirection (SSL)
https-redirection
The plugin allows an automatic redirection to the "HTTPS" version/URL of the site. Make your site SSL compatible easily.
SSL Insecure Content Fixer
ssl-insecure-content-fixer
Clean up WordPress website HTTPS insecure content
Temporary Login Without Password
temporary-login-without-password
Create self-expiring, temporary admin accounts. Easily share direct login links (no need for username/password) with your developers or editors.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
Send Secrets By Kaboom Developer Profile
2 plugins · 100 total installs
How We Detect Send Secrets By Kaboom
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kaboom-send-secrets/view/style.css/wp-content/plugins/kaboom-send-secrets/view/script.jsHTML / DOM Fingerprints
kaboom-headershortcodedata-errordata-error-iddata-error-messagewindow.location.reload()[stand_alone_send_secret]