Monetize WP Security & Risk Analysis

wordpress.org/plugins/monetize-wp

Wordpress Plugin that helps you monetize your wordpress site easily. Currently includes both websites that pay money and cryptocurrency.

10 active installs v1.3 PHP 5.2.1+ WP 4.9.6+ Updated Mar 2, 2019
adflybitcoincoinmediamake-moneymonetize-wp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Monetize WP Safe to Use in 2026?

Generally Safe

Score 85/100

Monetize WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "monetize-wp" plugin v1.3 exhibits a mixed security posture. While it demonstrates good practices in terms of SQL query handling, with 100% of queries using prepared statements and no external HTTP requests, several areas of concern are present. A significant weakness lies in its attack surface, with two AJAX handlers lacking authentication checks, creating potential entry points for unauthorized actions. The limited output escaping (27% properly escaped) also suggests a risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data might not be adequately sanitized before being displayed. The absence of nonce checks and capability checks on these AJAX handlers further exacerbates the risk of unauthorized access and manipulation. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this clean history, combined with the identified code quality issues, could indicate that the plugin has not been thoroughly audited or that potential vulnerabilities have not yet been discovered or reported. In conclusion, while the plugin avoids common pitfalls like raw SQL and external requests, the unprotected AJAX endpoints and inadequate output escaping represent significant security weaknesses that require immediate attention to mitigate risks.

Key Concerns

  • AJAX handlers without auth checks
  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
  • Use of dangerous function (create_function)
Vulnerabilities
None known

Monetize WP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Monetize WP Release Timeline

v1.3Current
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Monetize WP Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
0 prepared
Unescaped Output
104
39 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'register_widget("monetize_wordpress_solvemedia_fullpwordpress-money.php:17
create_functionadd_action('widgets_init', create_function('', 'register_widget("monetize_wordpress_solvemedia_custowordpress-money.php:20
create_functionadd_action('widgets_init', create_function('', 'register_widget("monetize_wordpress_custom_ads_Widgewordpress-money.php:24

Output Escaping

27% escaped143 total outputs
Attack Surface
2 unprotected

Monetize WP Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 2

authwp_ajax_monetize_wordpress_ajax_solvemedia_checkoptions.php:1358
noprivwp_ajax_monetize_wordpress_ajax_solvemedia_checkoptions.php:1359

Shortcodes 2

[mw_sm_custom_locker] wordpress-money.php:32
[mw_sm_custom_ad] wordpress-money.php:109
WordPress Hooks 28
actionadmin_menuoptions.php:4
actionadmin_initoptions.php:8
actionadmin_enqueue_scriptsoptions.php:1187
actionwp_enqueue_scriptsoptions.php:1205
actionadmin_enqueue_scriptsoptions.php:1212
filterscript_loader_tagoptions.php:1225
actionwp_enqueue_scriptsoptions.php:1229
actionwp_headoptions.php:1282
actionwp_headoptions.php:1308
actionadmin_noticesoptions.php:1321
actionwp_dropdown_pagesoptions.php:1330
actionlogin_formoptions.php:1380
actionlogin_enqueue_scriptsoptions.php:1384
actionwp_authenticate_useroptions.php:1404
actionregister_formoptions.php:1424
filterregistration_errorsoptions.php:1443
actionlostpassword_formoptions.php:1463
actionlostpassword_postoptions.php:1482
filterthe_contentoptions.php:1492
filterthe_contentoptions.php:1499
actionwidgets_initoptions.php:1511
actionwp_footerwordpress-money-solvemedia-custom-locker-widget.php:39
actionwp_footerwordpress-money-solvemedia-fullpage-locker-widget.php:30
actionplugins_loadedwordpress-money.php:14
actionwidgets_initwordpress-money.php:17
actionwidgets_initwordpress-money.php:20
actionwidgets_initwordpress-money.php:24
actionwp_footerwordpress-money.php:80
Maintenance & Trust

Monetize WP Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 2, 2019
PHP min version5.2.1
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Monetize WP Developer Profile

Kane G

3 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Monetize WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/monetize-wp/solvemedia_main.js/wp-content/plugins/monetize-wp/solvemedia_ad.js
Script Paths
http://api.contentunlock.net/js/cu.jshttp://api-secure.contentunlock.net/js/cu.js

HTML / DOM Fingerprints

CSS Classes
coinmedia_title
Data Attributes
data-keydata-serverdata-protocoldata-xpath-bodydata-xpath-footdata-tease-header+3 more
JS Globals
solvemedia_mainsolvemedia_ad
Shortcode Output
<ins class="acunlock"<div class="coinmedia_title">
FAQ

Frequently Asked Questions about Monetize WP