Kw Modern Advertise Security & Risk Analysis

wordpress.org/plugins/kw-modern-advertise

Make background images clickable with randomize options and priority displaying option.

10 active installs v1.2.3 PHP + WP 3.0+ Updated Unknown
advertiserbackgroundmodern-advertisemodern-advertise-zonepartner
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kw Modern Advertise Safe to Use in 2026?

Generally Safe

Score 100/100

Kw Modern Advertise has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "kw-modern-advertise" plugin v1.2.3 presents a mixed security posture. On the positive side, there is no recorded vulnerability history, suggesting a potentially well-maintained or less targeted plugin. The static analysis also indicates a small attack surface with no publicly documented entry points like AJAX handlers, REST API routes, or shortcodes without authentication checks, which is a strong security indicator.

However, significant concerns arise from the code signals. The most critical finding is that 100% of output is not properly escaped, posing a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis reveals two flows with unsanitized paths, both flagged as high severity. These indicate potential pathways where untrusted input could be processed without adequate sanitization, leading to security issues. The absence of nonce and capability checks further exacerbates these risks, as there are no built-in mechanisms to verify user authorization or prevent Cross-Site Request Forgery (CSRF) on any identified entry points (even though the attack surface appears limited).

While the plugin's lack of historical CVEs is reassuring, the current static analysis reveals critical areas for improvement. The high percentage of unescaped output combined with unsanitized taint flows is a significant weakness that needs immediate attention. The absence of nonce and capability checks, while not directly indicated as exploitable due to the limited attack surface, represents a missed security best practice that could become an issue if new entry points are added or if existing ones have subtle bypasses. Therefore, despite the clean vulnerability history, the internal code analysis flags substantial risks.

Key Concerns

  • 100% of output not properly escaped
  • 2 high severity unsanitized taint flows
  • 0 nonce checks
  • 0 capability checks
Vulnerabilities
None known

Kw Modern Advertise Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kw Modern Advertise Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
28 prepared
Unescaped Output
30
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
6
External Requests
0
Bundled Libraries
0

SQL Query Safety

97% prepared29 total queries

Output Escaping

0% escaped30 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
kw_advert (kw-modern-advertise.php:443)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Kw Modern Advertise Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_footerkw-modern-advertise.php:50
filterthe_contentkw-modern-advertise.php:157
actionplugins_loadedkw-modern-advertise.php:402
actionadmin_menukw-modern-advertise.php:435
Maintenance & Trust

Kw Modern Advertise Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedUnknown
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Kw Modern Advertise Developer Profile

leaklords

7 plugins · 70 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kw Modern Advertise

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/kw-modern-advertise/css/admin.css
Script Paths
/wp-content/plugins/kw-modern-advertise/js/jpages.min.js

HTML / DOM Fingerprints

CSS Classes
cliczone-advert-leftcliczone-advert-rightkma-wrapper
Shortcode Output
<div id="kma-wrapper"><a href=""><div id="cliczone-advert-left">&nbsp;</div></a><a href=""><div id="cliczone-advert-right">&nbsp;</div></a></div>
FAQ

Frequently Asked Questions about Kw Modern Advertise