MANTIS Ad Network Security & Risk Analysis

wordpress.org/plugins/mantis-ad-network

Easily serve advertisements from the MANTIS Ad Network on your website.

100 active installs v1.7.2 PHP + WP 3.7.0+ Updated Jan 30, 2023
adsadvertisementmantis
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MANTIS Ad Network Safe to Use in 2026?

Generally Safe

Score 85/100

MANTIS Ad Network has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'mantis-ad-network' v1.7.2 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no known vulnerabilities or CVEs in its history. It also reports zero taint flows, indicating no immediate concerns regarding sensitive data manipulation or injection vulnerabilities that could be identified through this analysis. The attack surface is minimal, with only one shortcode and no unprotected AJAX handlers or REST API routes.

However, significant concerns arise from the complete lack of output escaping. With 21 total outputs and 0% properly escaped, this presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed on the front-end or back-end without proper sanitization could be exploited to inject malicious scripts. Furthermore, the absence of nonce checks and capability checks on its entry points (even though the attack surface is small) is a weakness that, when combined with unescaped output, can increase the likelihood and impact of potential attacks, especially if the single shortcode is exposed to user-controlled input.

In conclusion, while the plugin is free from known vulnerabilities and uses secure database practices, the pervasive issue of unescaped output poses a substantial security risk. The lack of nonce and capability checks on its entry points further exacerbates this risk. Addressing the output escaping and implementing robust authentication checks on its entry points are critical steps to improve its security.

Key Concerns

  • 0% properly escaped output
  • 0 Nonce checks
  • 0 Capability checks
Vulnerabilities
None known

MANTIS Ad Network Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MANTIS Ad Network Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped21 total outputs
Attack Surface

MANTIS Ad Network Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mantis_video] mantis.php:134
WordPress Hooks 16
actionadmin_menuadmin.php:7
actionadmin_noticesadmin.php:8
actionadmin_initadmin.php:9
filterthe_contentafter.php:41
actioninitafter.php:46
actionwp_footermantis.php:47
actionwp_footermantis.php:51
actioninitmantis.php:54
filteroembed_fetch_urlmantis.php:105
actioninitmantis.php:110
filterthe_contentrecommend.php:51
filtercomments_templaterecommend.php:55
actioninitrecommend.php:60
actionwp_footerwidget.php:18
actionwidgets_initwidget.php:109
actionwoocommerce_thankyouwoocommerce.php:22
Maintenance & Trust

MANTIS Ad Network Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 30, 2023
PHP min version
Downloads9K

Community Trust

Rating60/100
Number of ratings8
Active installs100
Developer Profile

MANTIS Ad Network Developer Profile

Paris Holley

2 plugins · 300 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MANTIS Ad Network

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mantis-ad-network/js/mantis-ads.js/wp-content/plugins/mantis-ad-network/css/mantis-ads.css
Script Paths
/wp-content/plugins/mantis-ad-network/js/mantis-ads.js
Version Parameters
mantis-ad-network/js/mantis-ads.js?ver=mantis-ad-network/css/mantis-ads.css?ver=

HTML / DOM Fingerprints

CSS Classes
mantis-floatmantis-display
Data Attributes
data-mantis-zone
Shortcode Output
<div class='mantis-display
FAQ

Frequently Asked Questions about MANTIS Ad Network