
MadTek Entrusans ™ IDS client Security & Risk Analysis
wordpress.org/plugins/madtek-entrusansEffective website security requires a combination of tools and best practices to operate WordPress safely on today’s internet.
Is MadTek Entrusans ™ IDS client Safe to Use in 2026?
Generally Safe
Score 85/100MadTek Entrusans ™ IDS client has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "madtek-entrusans" v2.0.6 plugin exhibits a concerning security posture primarily due to its unprotected REST API route and a lack of output escaping. While the plugin avoids dangerous functions, SQL injection via prepared statements, and file operations, the single unprotected REST API endpoint represents a significant attack vector that could be exploited by unauthenticated users. The analysis also indicates that a high percentage of output operations are not properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The absence of any recorded vulnerability history might suggest a lack of past exploitation or disclosure, but this should not be relied upon as an indicator of current security. The plugin's strengths lie in its use of prepared statements for SQL queries and the absence of known CVEs, but these are overshadowed by the critical issues in its entry points and output handling.
The taint analysis, while showing no critical or high severity unsanitized paths, did reveal two flows with unsanitized paths. Combined with the unprotected REST API, this suggests a potential for unintended data processing or injection. The complete lack of nonce and capability checks further exacerbates these risks, meaning that actions performed through the unprotected REST API are not protected against CSRF or unauthorized access based on user roles. Overall, the plugin requires immediate attention to address the unprotected REST API and improve output escaping to mitigate potential security threats.
Key Concerns
- Unprotected REST API route
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
- Taint flows with unsanitized paths
MadTek Entrusans ™ IDS client Security Vulnerabilities
MadTek Entrusans ™ IDS client Release Timeline
MadTek Entrusans ™ IDS client Code Analysis
Output Escaping
Data Flow Analysis
MadTek Entrusans ™ IDS client Attack Surface
REST API Routes 1
WordPress Hooks 7
Maintenance & Trust
MadTek Entrusans ™ IDS client Maintenance & Trust
Maintenance Signals
Community Trust
MadTek Entrusans ™ IDS client Alternatives
Catch IDs
catch-ids
What this plugin does is to shows the IDs on admin section.
Catch Web Tools
catch-web-tools
A top-notch modular plugin that can greatly enhance the capabilities of a WordPress website with its powerful features.
Lockdown WP Admin
lockdown-wp-admin
Lockdown WP Admin conceals the administration and login screen from intruders. It can hide WordPress Admin (/wp-admin/) and and login (/wp-login.
Show Pages IDs
show-posts-and-pages-id
This plugin will show the IDs of posts and pages on the admin bar and on the admin panel.
Simply Show IDs
simply-show-ids
Simply shows the ID of Posts, Pages, Media, Links, Categories, Tags and Users in the admin tables for easy access.
MadTek Entrusans ™ IDS client Developer Profile
1 plugin · 0 total installs
How We Detect MadTek Entrusans ™ IDS client
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/madtek-entrusans/admin/css/madtek-entrusans-admin.css/wp-content/plugins/madtek-entrusans/admin/js/madtek-entrusans-admin.js/wp-content/plugins/madtek-entrusans/admin/js/madtek-entrusans-admin.jsmadtek-entrusans-admin.css?ver=madtek-entrusans-admin.js?ver=HTML / DOM Fingerprints
entrusans-info This function is provided for demonstration purposes only. An instance of this class should be passed to the run() function defined in Plugin_Name_Loader as all of the hooks are defined in that particular class. +5 more<h3>Entrusans™ Intrusion Detection Service</h3><h4>Status: Active</h4><h4>License Key: