LH Multisite Ads Security & Risk Analysis

wordpress.org/plugins/lh-multisite-ads

Allows you to insert ads after paragraphs of your post content, throughout your multisite network.

10 active installs v1.26 PHP + WP 4.0+ Updated Sep 8, 2019
adsadsenseadvertisinggoogle-adsensemultisite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LH Multisite Ads Safe to Use in 2026?

Generally Safe

Score 85/100

LH Multisite Ads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "lh-multisite-ads" v1.26 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant positive. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating nonce and capability checks, albeit limited in scope. The lack of dangerous functions, file operations, and external HTTP requests also contributes to a reduced attack surface.

However, a notable concern arises from the output escaping. With 15 total outputs and only 40% properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that untrusted data could be injected into the plugin's output, potentially leading to malicious code execution in a user's browser. The taint analysis showing zero flows is positive, but it's crucial to remember that this is based on the limited entry points and may not capture all potential taint paths, especially if output escaping issues are present.

The plugin's vulnerability history is remarkably clean, with zero recorded CVEs. This suggests a history of responsible development and potentially a good track record of addressing any past issues. However, the clean history alone should not be relied upon as a sole indicator of current security, especially given the identified output escaping weakness. Overall, while the plugin has a strong foundation and low attack surface, the significant percentage of unescaped output presents a tangible risk that requires attention.

Key Concerns

  • Significant amount of unescaped output
Vulnerabilities
None known

LH Multisite Ads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LH Multisite Ads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
6 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped15 total outputs
Attack Surface

LH Multisite Ads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitlh-multisite-ads.php:512
actionadd_meta_boxeslh-multisite-ads.php:513
actionsave_postlh-multisite-ads.php:514
actionadmin_menulh-multisite-ads.php:515
filterthe_contentlh-multisite-ads.php:516
filterpost_updated_messageslh-multisite-ads.php:517
filterenter_title_herelh-multisite-ads.php:518
filterplugin_action_linkslh-multisite-ads.php:519
actionplugins_loadedlh-multisite-ads.php:549
Maintenance & Trust

LH Multisite Ads Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedSep 8, 2019
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

LH Multisite Ads Developer Profile

shawfactor

77 plugins · 15K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect LH Multisite Ads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lh-multisite-ads/css/style.css/wp-content/plugins/lh-multisite-ads/js/admin.js
Version Parameters
lh-multisite-ads/css/style.css?ver=lh-multisite-ads/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
lh_multisite_ads-ads_div
Data Attributes
data-lh_multisite_ads-advert-code-div
JS Globals
lh_multisite_ads
FAQ

Frequently Asked Questions about LH Multisite Ads