
MatCMS Security & Risk Analysis
wordpress.org/plugins/matcmsThis plugin adds to WordPress some utilities for developers.
Is MatCMS Safe to Use in 2026?
Generally Safe
Score 100/100MatCMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of matcms v1.7.0 reveals a generally strong security posture, with no identified attack surface, dangerous functions, file operations, external HTTP requests, or taint vulnerabilities. The plugin also demonstrates good practices in output escaping, with 95% of outputs being properly handled. The lack of any recorded CVEs, both past and present, further suggests a history of security diligence or minimal exposure to common attack vectors.
However, a significant concern is the presence of a single SQL query that does not utilize prepared statements, leaving it potentially vulnerable to SQL injection. Furthermore, the complete absence of nonce checks and capability checks on any entry points, while the attack surface is currently zero, is a weakness that could become problematic if new entry points are introduced without proper authentication and authorization. The current lack of vulnerability history is positive, but the identified SQL query issue highlights that even seemingly secure plugins can harbor specific, exploitable flaws.
Key Concerns
- SQL query without prepared statements
- No nonce checks on any entry points
- No capability checks on any entry points
MatCMS Security Vulnerabilities
MatCMS Code Analysis
SQL Query Safety
Output Escaping
MatCMS Attack Surface
WordPress Hooks 3
Maintenance & Trust
MatCMS Maintenance & Trust
Maintenance Signals
Community Trust
MatCMS Alternatives
Hide products count
hide-products-count
Hide products count in category view in WooCommerce
Premmerce Dev Tools
premmerce-dev-tools
This plugin is created to facilitate the development, testing and debugging of the code on the WordPress platform and to quickly create the demo data …
WP Utility Script Runner
wp-utility-script-runner
Create custom scripts and manage them directly from the WordPress Dashboard. Schedule scripts, handle user input, download reports, and more.
Admin Page Framework
admin-page-framework
Facilitates WordPress plugin and theme development.
Get Tweets in PHP
get-tweets-in-php
Get latest tweets from a Twitter account with a couple of lines of PHP, and do anything you want with them.
MatCMS Developer Profile
2 plugins · 10 total installs
How We Detect MatCMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/matcms/js/bootstrap-lightbox-init-images.jsHTML / DOM Fingerprints
paginationpage-itemactivedisabledpage-linkdata-bs-toggledata-bs-target