
Management & Maintenance Records Security & Risk Analysis
wordpress.org/plugins/managementmaintainence-recordingThis plugin add a dashboard widget to record admin activity on website. Simple to remember it
Is Management & Maintenance Records Safe to Use in 2026?
Generally Safe
Score 85/100Management & Maintenance Records has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'managementmaintainence-recording' plugin version 0.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, avoiding dangerous functions, and having no recorded historical vulnerabilities. This suggests a developer who is at least aware of common security pitfalls.
However, significant concerns arise from the static analysis. The presence of a single REST API route without a permission callback creates a clear attack vector. This unprotected entry point could allow unauthorized users to interact with the plugin's functionality, potentially leading to data manipulation or other unintended consequences. While taint analysis shows no critical or high severity flows, the lack of nonces on AJAX handlers (though there are none in this specific version) and the 53% rate of properly escaped output still indicate areas for improvement in input validation and output sanitization to prevent potential cross-site scripting (XSS) vulnerabilities.
Given the lack of historical vulnerabilities and the use of prepared statements, the immediate risk is not catastrophic. However, the unprotected REST API route represents a tangible and exploitable vulnerability that needs immediate attention. The plugin's current security is compromised by this single, critical oversight in its attack surface.
Key Concerns
- REST API route without permission callback
- Inconsistent output escaping (53% escaped)
Management & Maintenance Records Security Vulnerabilities
Management & Maintenance Records Code Analysis
Output Escaping
Management & Maintenance Records Attack Surface
REST API Routes 1
WordPress Hooks 3
Maintenance & Trust
Management & Maintenance Records Maintenance & Trust
Maintenance Signals
Community Trust
Management & Maintenance Records Alternatives
FixReport – Maintenance Logger
fixreport-maintenance-logger
Easily log website maintenance tasks, errors, and updates. Track your WordPress site's history, manage fixes effectively, and export your logs to PDF.
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Maintenance
maintenance
Great looking maintenance, coming soon & under construction pages. Put your site under maintenance in minutes.
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode
coming-soon
Easy Drag & Drop Page Builder. A complete solution to create a WordPress Website, Custom Themes, Landing Pages, Coming Soon & Maintenance Mode Pages.
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
Management & Maintenance Records Developer Profile
5 plugins · 320 total installs
How We Detect Management & Maintenance Records
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
mmrredgreenbluepurplegreydatenotename="mmr_deletename="date"name="type"name="description"/mmr/v1/activities