
LWS Tools Security & Risk Analysis
wordpress.org/plugins/lws-toolsOptimize and modify your website's parameters
Is LWS Tools Safe to Use in 2026?
Generally Safe
Score 98/100LWS Tools has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "lws-tools" v2.6.2 exhibits a mixed security posture. While it demonstrates good practices in output escaping (96%) and a lack of critical taint analysis findings, several areas raise concern. The presence of 2 AJAX handlers without authentication checks presents a direct attack vector, particularly as the plugin has a history of missing authorization vulnerabilities. Furthermore, the relatively low percentage of SQL queries using prepared statements (21%) combined with a history of high-severity vulnerabilities suggests a potential for SQL injection if not carefully managed, even though no direct taint flows were identified in this analysis. The vulnerability history, including two high-severity issues and a recent one in June 2023, points to a pattern of authorization and CSRF weaknesses, indicating that despite current unpatched status, a recurring security flaw exists. The plugin's strengths lie in its minimal external HTTP requests and good output escaping, but the identified unprotected entry points and historical vulnerabilities necessitate caution.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of prepared SQL statements
- History of high-severity vulnerabilities (2)
- History of medium-severity vulnerabilities (1)
- Bundled outdated library: DataTables v1.12.1
LWS Tools Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
LWS Tools <= 2.4.1 - Cross-Site Request Forgery
LWS Tools <= 2.3.1 - Cross-Site Request Forgery
LWS Plugins <= (Various Versions) - Missing Authorization Checks
LWS Tools Release Timeline
LWS Tools Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
LWS Tools Attack Surface
AJAX Handlers 25
WordPress Hooks 38
Maintenance & Trust
LWS Tools Maintenance & Trust
Maintenance Signals
Community Trust
LWS Tools Alternatives
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Admin Menu Editor
admin-menu-editor
Lets you edit the WordPress admin menu. You can re-order, hide or rename menus, add custom menus and more.
InfiniteWP Client
iwp-client
Install this plugin on unlimited sites and manage them all from a central dashboard. This plugin communicates with your InfiniteWP Admin Panel.
LWS Cleaner
lws-cleaner
Clean everything on your website easily!
LWS Hide Login
lws-hide-login
Secure your access to the admin page with this plugin !
LWS Tools Developer Profile
6 plugins · 78K total installs
How We Detect LWS Tools
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lws-tools/css/lws_tools_support_css.css/wp-content/plugins/lws-tools/css/lws_tk_style.css/wp-content/plugins/lws-tools/DataTables/datatables.min.css/wp-content/plugins/lws-tools/css/bootstrap.css/wp-content/plugins/lws-tools/js/bootstrap.min.js/wp-content/plugins/lws-tools/css/lws_tk_style_out.css/wp-content/plugins/lws-tools/DataTables/datatables.min.jslws_tools_support_css?ver=lws_tk_style.css?ver=datatables.min.css?ver=datatables.min.js?ver=bootstrap.css?ver=bootstrap.min.js?ver=lws_tk_style_out.css?ver=HTML / DOM Fingerprints
lwstk_review_block_generallwstk_circlelwstk_review_block_imagelwstk_review_block_titlelwstk_review_block_desclwstk_button_rate_pluginlwstk_review_button_secondaryanimationFadeOut+3 more<!-- AJAX Reminder --><!-- AJAX Reminder -->id="lwstk_review_notice"src="<?php echo esc_url(plugins_url('images/plugin_lws-tools.svg', __FILE__)) ?>"src="<?php echo esc_url(plugins_url('images/noter.svg', __FILE__)) ?>"ajaxurllwstk_remind_melwstk_do_not_bother_me