Modular DS: Monitor, update, and backup multiple websites Security & Risk Analysis

wordpress.org/plugins/modular-connector

Manage all your WordPress sites from one place. Automate updates, backups, uptime monitoring, security, maintenance reports, and more.

40K active installs v2.7.5 PHP 7.4+ WP 6.0+ Updated Mar 11, 2026
backupbackupsmonitoringsecurityupdate
87
A · Safe
CVEs total3
Unpatched0
Last CVEMar 10, 2026
Safety Verdict

Is Modular DS: Monitor, update, and backup multiple websites Safe to Use in 2026?

Generally Safe

Score 87/100

Modular DS: Monitor, update, and backup multiple websites has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Mar 10, 2026Updated 23d ago
Risk Assessment

The "modular-connector" plugin v2.7.5 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified entry points without authentication, all SQL queries utilize prepared statements, and there are no critical or high severity taint analysis findings. The presence of nonce and capability checks, along with proper output escaping on a majority of outputs, suggests some adherence to secure coding practices.

However, significant concerns arise from its vulnerability history. The plugin has a past of 3 known CVEs, with 2 being critical and 1 medium. The common vulnerability types being CSRF and Improper Privilege Management are particularly worrying as they can lead to unauthorized actions and elevation of privileges. While there are currently no unpatched vulnerabilities, the historical prevalence of critical issues is a strong indicator of past weaknesses in secure development, potentially hinting at underlying architectural flaws or recurring insecure patterns.

In conclusion, while the immediate static analysis for v2.7.5 doesn't reveal readily exploitable vulnerabilities like raw SQL or direct attack surface exposure, the plugin's past vulnerability record, especially the critical ones, warrants a cautious approach. The presence of a bundled library (Guzzle) could also introduce risks if it's outdated or has known vulnerabilities. The low number of file operations and external HTTP requests is a positive indicator, but the overall risk is elevated due to historical critical vulnerabilities.

Key Concerns

  • Past critical vulnerabilities
  • Past medium vulnerability
  • Bundled library (Guzzle)
  • Output escaping only 63% proper
Vulnerabilities
3

Modular DS: Monitor, update, and backup multiple websites Security Vulnerabilities

CVEs by Year

3 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

Critical
2
Medium
1

3 total CVEs

CVE-2026-3903medium · 4.3Cross-Site Request Forgery (CSRF)

Modular Connector <= 2.5.1 - Cross-Site Request Forgery via postConfirmOauth

Mar 10, 2026 Patched in 2.6.0 (1d)
CVE-2026-23800critical · 9.8Improper Privilege Management

Modular DS 2.5.2 - Unauthenticated Privilege Escalation

Jan 16, 2026 Patched in 2.6.0 (4d)
CVE-2026-23550critical · 9.8Improper Privilege Management

Modular DS <= 2.5.1 - Unauthenticated Privilege Escalation

Jan 14, 2026 Patched in 2.5.2 (9d)
Code Analysis
Analyzed Mar 16, 2026

Modular DS: Monitor, update, and backup multiple websites Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
9 prepared
Unescaped Output
6
10 escaped
Nonce Checks
3
Capability Checks
1
File Operations
18
External Requests
4
Bundled Libraries
1

Bundled Libraries

Guzzle

SQL Query Safety

100% prepared9 total queries

Output Escaping

63% escaped16 total outputs
Attack Surface

Modular DS: Monitor, update, and backup multiple websites Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
filterplugin_action_linkssrc\app\Providers\ModularConnectorServiceProvider.php:62
filterupgrader_package_optionssrc\app\Services\Manager\ManagerPlugin.php:56
filterupgrader_package_optionssrc\app\Services\Manager\ManagerTheme.php:56
filterall_pluginssrc\app\Services\ManagerWhiteLabel.php:25
filterdebug_informationsrc\app\Services\ManagerWhiteLabel.php:26
filterplugin_row_metasrc\app\Services\ManagerWhiteLabel.php:27
actionadmin_enqueue_scriptssrc\app\Services\ManagerWhiteLabel.php:28
filtershow_advanced_pluginssrc\app\Services\ManagerWhiteLabel.php:29
actionadmin_menusrc\app\Services\ManagerWhiteLabel.php:30
actionadmin_enqueue_scriptssrc\app\WordPress\Admin.php:21
actionadmin_menusrc\app\WordPress\Admin.php:22
actionadmin_noticessrc\app\WordPress\Admin.php:23
actiontemplate_redirectsrc\app\WordPress\Admin.php:24
actionadmin_initsrc\app\WordPress\Admin.php:25
Maintenance & Trust

Modular DS: Monitor, update, and backup multiple websites Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4
Downloads1.0M

Community Trust

Rating100/100
Number of ratings96
Active installs40K
Developer Profile

Modular DS: Monitor, update, and backup multiple websites Developer Profile

Modular DS

1 plugin · 40K total installs

91
trust score
Avg Security Score
87/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Modular DS: Monitor, update, and backup multiple websites

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/modular-connector/assets/css/admin.css/wp-content/plugins/modular-connector/assets/js/admin.js/wp-content/plugins/modular-connector/assets/js/vendor.js
Script Paths
/wp-content/plugins/modular-connector/assets/js/admin.js/wp-content/plugins/modular-connector/assets/js/vendor.js
Version Parameters
modular-connector/assets/css/admin.css?ver=modular-connector/assets/js/admin.js?ver=modular-connector/assets/js/vendor.js?ver=

HTML / DOM Fingerprints

CSS Classes
modular-connector-settingsmc-settings-tabmc-tab-contentmc-sectionmc-field-group
HTML Comments
<!-- Generated by Modular Connector --><!-- Do not remove. It is automatically disabled when disabling the main plugin. --><!-- Silence is golden. -->
Data Attributes
data-modular-connector-tabdata-modular-connector-action
JS Globals
modular_connector_config
REST Endpoints
/wp-json/modular-connector/v1/settings/wp-json/modular-connector/v1/stats/wp-json/modular-connector/v1/backup
FAQ

Frequently Asked Questions about Modular DS: Monitor, update, and backup multiple websites