LexonAds: Free Ad Network – Boost Traffic & Get More Visitors Security & Risk Analysis

wordpress.org/plugins/martins-free-and-easy-ad-network-get-more-visitors

The 100% free alternative to Google Ads and Facebook Ads. Join our global ad exchange network to get more website visitors and boost your visibility a …

100 active installs v1.0.9 PHP 5.6+ WP 5.0+ Updated Apr 7, 2026
ad-exchangeadsense-alternativeadvertisingmarketingtraffic
79
B · Generally Safe
CVEs total1
Unpatched1
Last CVEMay 7, 2025
Safety Verdict

Is LexonAds: Free Ad Network – Boost Traffic & Get More Visitors Safe to Use in 2026?

Mostly Safe

Score 79/100

LexonAds: Free Ad Network – Boost Traffic & Get More Visitors is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: May 7, 2025Updated 1mo ago
Risk Assessment

The plugin "martins-free-and-easy-ad-network-get-more-visitors" v1.0.6 exhibits a mixed security posture. On the positive side, the static analysis indicates excellent adherence to secure coding practices, with all identified SQL queries using prepared statements and all output being properly escaped. There are no dangerous functions, file operations, or bundled libraries to flag. However, the lack of any explicit nonce checks or capability checks across the entire attack surface, coupled with two flows with unsanitized paths, raises significant concerns about the potential for privilege escalation or unauthorized actions.

The vulnerability history is a major red flag. The presence of a known, unpatched medium-severity vulnerability, specifically identified as Cross-Site Request Forgery (CSRF), is a critical weakness. The fact that this is the plugin's last known vulnerability suggests a pattern that requires immediate attention. While the code analysis shows no readily apparent exploitable vulnerabilities like raw SQL or unsanitized inputs in common attack vectors, the combination of missing authorization checks and a history of CSRF indicates a significant risk.

In conclusion, while the developer has implemented some strong security measures like prepared statements and output escaping, the absence of robust authorization checks and the presence of an unpatched CSRF vulnerability create a substantial security risk. Users of this plugin should be aware of these potential weaknesses and prioritize updating if a patched version becomes available or consider alternative solutions.

Key Concerns

  • Unpatched CVE
  • Flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
1 published

LexonAds: Free Ad Network – Boost Traffic & Get More Visitors Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-47620medium · 4.3Cross-Site Request Forgery (CSRF)

Martins Free Monetized Ad Exchange Network <= 1.0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting

May 7, 2025Unpatched
Version History

LexonAds: Free Ad Network – Boost Traffic & Get More Visitors Release Timeline

v1.0.9Current1 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
Code Analysis
Analyzed Mar 16, 2026

LexonAds: Free Ad Network – Boost Traffic & Get More Visitors Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
saveSettings (martinsAdNetwork.php:131)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LexonAds: Free Ad Network – Boost Traffic & Get More Visitors Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwp_enqueue_scriptsmartinsAdNetwork.php:28
filterscript_loader_tagmartinsAdNetwork.php:29
actionadmin_initmartinsAdNetwork.php:72
actionadmin_menumartinsAdNetwork.php:73
actionadmin_headmartinsAdNetwork.php:74
actionadmin_post_add_martins_ad_network_settingsmartinsAdNetwork.php:77
Maintenance & Trust

LexonAds: Free Ad Network – Boost Traffic & Get More Visitors Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.0
Last updatedApr 7, 2026
PHP min version5.6
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

LexonAds: Free Ad Network – Boost Traffic & Get More Visitors Developer Profile

bundgaard

3 plugins · 1K total installs

80
trust score
Avg Security Score
88/100
Avg Patch Time
78 days
View full developer profile
Detection Fingerprints

How We Detect LexonAds: Free Ad Network – Boost Traffic & Get More Visitors

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/martins-free-and-easy-ad-network-get-more-visitors/assets/css/style.css
Script Paths
https://adnetwork.martinstools.com/assets/js/ad-network.js

HTML / DOM Fingerprints

Data Attributes
data-clientdata-themedata-positiondata-offset
FAQ

Frequently Asked Questions about LexonAds: Free Ad Network – Boost Traffic & Get More Visitors