
MQTT-Plug Security & Risk Analysis
wordpress.org/plugins/mqtt-plugReal-time MQTT dashboards inside WordPress. Connect securely over WebSocket (WS/WSS) and visualize live IoT data, logs, and events.
Is MQTT-Plug Safe to Use in 2026?
Generally Safe
Score 100/100MQTT-Plug has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mqtt-plug" plugin version 1.0 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive sign. The plugin exclusively uses prepared statements for SQL queries, which is a best practice for preventing SQL injection vulnerabilities. Furthermore, the plugin has a strong output escaping rate (87%), indicating an effort to mitigate cross-site scripting (XSS) risks. The capability checks are also present, which is important for authorization.
Key Concerns
- Missing nonce checks on entry points
- 13% of outputs are not properly escaped
MQTT-Plug Security Vulnerabilities
MQTT-Plug Code Analysis
Output Escaping
MQTT-Plug Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
MQTT-Plug Maintenance & Trust
Maintenance Signals
Community Trust
MQTT-Plug Alternatives
LED-SITE-INDICATOR
led-site-indicator
LED-SITE-INDICATOR connects WordPress to the LED Website Indicator IOT device.
Mesh-Plug for Meshtastic
mesh-plug
Lightweight Meshtastic/MQTT viewer for WordPress via MQTT over WebSocket (WS/WSS).
Piotnet Forms
piotnetforms
Piotnet Forms - Highly Customizable WordPress Form Builder
heatmap for WordPress – Realtime analytics
heatmap-for-wp
Real-time analytics and event tracking for your WordPress sites.
Live Carts for WooCommerce: Track Real-Time, Abandoned, and Converted Carts!
live-carts-for-woocommerce
Monitor your customers' current and past WooCommerce shopping carts via the WordPress admin.
MQTT-Plug Developer Profile
4 plugins · 10 total installs
How We Detect MQTT-Plug
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mqtt-plug/mqtt-plug.css/wp-content/plugins/mqtt-plug/mqtt-plug.js/wp-content/plugins/mqtt-plug/mqtt-plug.jsmqtt-plug/mqtt-plug.css?ver=mqtt-plug/mqtt-plug.js?ver=HTML / DOM Fingerprints
mqtt-plug-live-viewermqtt-plug-observer-viewerMQTT-Plug Live ViewerMQTT-Plug Observer Viewerdata-mqtt-plug-ws-urldata-mqtt-plug-usernamedata-mqtt-plug-passworddata-mqtt-plug-client-prefixdata-mqtt-plug-keepalivedata-mqtt-plug-reconnect-ms+10 moreMQTT_Plug_Config/wp-json/mqtt-plug/v1/status/wp-json/mqtt-plug/v1/snapshot[mqtt_plugmqtt_plug_live_viewermqtt_plug_observer_viewer