mm Content Manage Security & Risk Analysis

wordpress.org/plugins/mm-content-manage

Gestione del contenuto e del riassunto. Gestione di Posts e Pagine private.

10 active installs v1.1 PHP + WP 2.5.0+ Updated May 26, 2013
contentexcerptpostsprivate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is mm Content Manage Safe to Use in 2026?

Generally Safe

Score 85/100

mm Content Manage has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'mm-content-manage' plugin v1.1 exhibits a strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its potential attack surface. Furthermore, the code signals show a positive trend with no dangerous functions detected, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests that could be exploited. The presence of capability checks, although limited, is also a good sign.

However, a notable concern arises from the output escaping. With 8 total outputs and only 25% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied input displayed on the frontend or backend might not be sufficiently sanitized, allowing attackers to inject malicious scripts. The lack of any taint analysis results or historical vulnerabilities is positive but doesn't negate the immediate XSS risk identified in the output escaping. The absence of nonce checks on AJAX, while not applicable here due to 0 AJAX handlers, would typically be a concern.

In conclusion, while the plugin has commendable practices regarding its attack surface and SQL handling, the poor output escaping represents a critical weakness that requires immediate attention. Addressing the XSS risk is paramount for improving its overall security. The clean vulnerability history is a positive indicator, but proactive security measures, especially concerning output sanitization, are essential for maintaining this record.

Key Concerns

  • Insufficient output escaping leading to XSS risk
Vulnerabilities
None known

mm Content Manage Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

mm Content Manage Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
2 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped8 total outputs
Attack Surface

mm Content Manage Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterthe_contentMM_content_manage.php:49
actionadd_meta_boxesMM_content_manage.php:52
actionsave_postMM_content_manage.php:58
Maintenance & Trust

mm Content Manage Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedMay 26, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

mm Content Manage Developer Profile

mancabelli

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect mm Content Manage

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
id="MM_content_manage_radio_content"id="MM_content_manage_radio_excerpt"id="MM_content_manage_radio_private"id="MM_content_manage_text_cap"name="MM_content_manage_radio"name="MM_content_manage_text_cap"+3 more
Shortcode Output
[MORE]
FAQ

Frequently Asked Questions about mm Content Manage