MHT Entry Confirm Security & Risk Analysis

wordpress.org/plugins/mht-entry-confirm

Lightweight WordPress plugin to restrict content behind a confirmation modal — no tracking, no ads, privacy-friendly.

0 active installs v1.1.2 PHP 8.2+ WP 6.0+ Updated Mar 14, 2026
access-controlage-gateage-verificationcontent-restrictioncontent-warning
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MHT Entry Confirm Safe to Use in 2026?

Generally Safe

Score 100/100

MHT Entry Confirm has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The mht-entry-confirm plugin version 1.1.2 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any detected dangerous functions, raw SQL queries, file operations, external HTTP requests, or unsanitized taint flows is a significant positive. Furthermore, the high percentage of properly escaped output and the lack of any recorded vulnerabilities or CVEs indicate a well-developed and maintained plugin.

However, there are potential areas of concern that warrant consideration. The complete lack of any entry points (AJAX, REST API, shortcodes, cron events) is unusual. While this currently means no entry points are unprotected, it also suggests that the plugin's functionality might not be exposed in a standard WordPress way, or that the analysis might have missed certain integration points. More importantly, the complete absence of nonce checks and capability checks across all code signals a potential weakness. While no direct vulnerabilities are currently evident, this lack of fundamental security checks means that if any new functionality were to be introduced or if a way to interact with the plugin's code were discovered, it could be susceptible to Cross-Site Request Forgery (CSRF) or unauthorized action exploits.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

MHT Entry Confirm Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MHT Entry Confirm Release Timeline

v1.1.2Current
v1.1.1
v1.1.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

MHT Entry Confirm Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
62 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped66 total outputs
Attack Surface

MHT Entry Confirm Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initmht-entry-confirm-settings.php:11
actionadmin_menumht-entry-confirm-settings.php:13
actionadmin_enqueue_scriptsmht-entry-confirm-settings.php:34
actioninitmht-entry-confirm.php:51
actionwp_enqueue_scriptsmht-entry-confirm.php:67
actionwp_headmht-entry-confirm.php:68
Maintenance & Trust

MHT Entry Confirm Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version8.2
Downloads349

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MHT Entry Confirm Developer Profile

maid-h

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MHT Entry Confirm

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mht-entry-confirm/mht-entry-confirm.css/wp-content/plugins/mht-entry-confirm/mht-entry-confirm-front.js
Script Paths
/wp-content/plugins/mht-entry-confirm/mht-entry-confirm-front.js
Version Parameters
mht-entry-confirm/mht-entry-confirm.css?ver=mht-entry-confirm/mht-entry-confirm-front.js?ver=

HTML / DOM Fingerprints

CSS Classes
mhtentryconfirm_extra_check_wrappermhtentryconfirm_birth_date
Data Attributes
data-mhtentryconfirm
JS Globals
mhtentryconfirm_vars
FAQ

Frequently Asked Questions about MHT Entry Confirm