
MainWP Child Reports Security & Risk Analysis
wordpress.org/plugins/mainwp-child-reportsThe MainWP Child Report plugin tracks changes to Child sites for the Pro Reports Extension.
Is MainWP Child Reports Safe to Use in 2026?
Generally Safe
Score 96/100MainWP Child Reports has a strong security track record. Known vulnerabilities have been patched promptly.
The mainwp-child-reports plugin v2.2.6 demonstrates a generally strong security posture with excellent output escaping and a high percentage of prepared SQL statements. The absence of critical or high-severity taint flows and the presence of numerous nonce and capability checks are positive indicators. However, the plugin has a history of significant vulnerabilities, including two high-severity SQL injection flaws and a medium-severity CSRF issue. While there are no currently unpatched CVEs, this history suggests a recurring pattern of insecure coding practices that have led to past exploits. The presence of one AJAX handler without authentication checks represents a direct, exploitable entry point that significantly undermines the overall security, especially given the plugin's past SQL injection issues.
Key Concerns
- AJAX handler without auth check
- History of 2 High Severity CVEs
- History of 1 Medium Severity CVE
MainWP Child Reports Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
MainWP Child Reports <= 2.2 - Cross-Site Request Forgery to Arbitrary Options Update
MainWP Child Reports <= 2.1.1 - Cross-Site Request Forgery
MainWP Child Reports <= 2.0.7 - Admin+ SQL Injection
MainWP Child Reports Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
MainWP Child Reports Attack Surface
AJAX Handlers 7
WordPress Hooks 70
Scheduled Events 1
Maintenance & Trust
MainWP Child Reports Maintenance & Trust
Maintenance Signals
Community Trust
MainWP Child Reports Alternatives
MainWP Key Maker
mainwp-key-maker
The MainWP Key Maker plugin copies settings for the MainWP Bulk Settings Manager Extension.
MainWP Post SMTP Extension – Easily Manage WP SMTP Setup for All Sites in One Place
post-smtp-for-mainwp
Manage WP SMTP configuration from a single dashboard for all your sites. View email logs, get instant email failure alerts, and set up a backup SMTP c …
Update Brief for MainWP
update-brief-mainwp
Turn plain plugin update lists into compelling client reports that prove your maintenance value — powered by concise, professionally written update su …
WPvivid Backup for MainWP
wpvivid-backup-mainwp
Set up and control WPvivid Backup Free and Pro for all child sites directly from your MainWP Dashboard.
SEOPress for MainWP
seopress-for-mainwp
SEOPress for MainWP extension, is an-addon for MainWP and SEOPress plugins. Edit your SEOPress global settings directly from MainWP dashboard site.
MainWP Child Reports Developer Profile
4 plugins · 825K total installs
How We Detect MainWP Child Reports
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mainwp-child-reports/css/mainwp-child-reports-admin.css/wp-content/plugins/mainwp-child-reports/js/mainwp-child-reports-admin.js/wp-content/plugins/mainwp-child-reports/js/mainwp-child-reports-admin.jsmainwp-child-reports/css/mainwp-child-reports-admin.css?ver=mainwp-child-reports/js/mainwp-child-reports-admin.js?ver=HTML / DOM Fingerprints
wp_mainwp_stream_screendata-page-slugdata-noncewp_mainwp_stream_filters_nonce/wp-json/wp_mainwp_stream/v1/filters