
MQTT-Plug Security & Risk Analysis
wordpress.org/plugins/mqtt-plugReal-time MQTT dashboards inside WordPress. Connect securely over WebSocket (WS/WSS) and visualize live IoT data, logs, and events.
Is MQTT-Plug Safe to Use in 2026?
Generally Safe
Score 100/100MQTT-Plug has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mqtt-plug" plugin version 1.0 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive sign. The plugin exclusively uses prepared statements for SQL queries, which is a best practice for preventing SQL injection vulnerabilities. Furthermore, the plugin has a strong output escaping rate (87%), indicating an effort to mitigate cross-site scripting (XSS) risks. The capability checks are also present, which is important for authorization.
Key Concerns
- Missing nonce checks on entry points
- 13% of outputs are not properly escaped
MQTT-Plug Security Vulnerabilities
MQTT-Plug Release Timeline
MQTT-Plug Code Analysis
Output Escaping
MQTT-Plug Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
MQTT-Plug Maintenance & Trust
Maintenance Signals
Community Trust
MQTT-Plug Alternatives
LED-SITE-INDICATOR
led-site-indicator
LED-SITE-INDICATOR connects WordPress to the LED Website Indicator IOT device.
Mesh-Plug for Meshtastic
mesh-plug
Lightweight Meshtastic/MQTT viewer for WordPress via MQTT over WebSocket (WS/WSS).
WordSocket
wordsocket
WordSocket is the official WordPress plugin for WPSignal (wpsignal.io), a third-party WebSocket/SSE delivery service.
WP Data Access – App Builder for Tables, Forms, Charts, Maps & Dashboards
wp-data-access
Turn your data into WordPress apps with tables, forms, charts & maps — no code required, with optional hooks for developers. Supports 35+ languages.
Piotnet Forms
piotnetforms
Piotnet Forms - Highly Customizable WordPress Form Builder
MQTT-Plug Developer Profile
4 plugins · 20 total installs
How We Detect MQTT-Plug
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mqtt-plug/mqtt-plug.css/wp-content/plugins/mqtt-plug/mqtt-plug.js/wp-content/plugins/mqtt-plug/mqtt-plug.jsmqtt-plug/mqtt-plug.css?ver=mqtt-plug/mqtt-plug.js?ver=HTML / DOM Fingerprints
mqtt-plug-live-viewermqtt-plug-observer-viewerMQTT-Plug Live ViewerMQTT-Plug Observer Viewerdata-mqtt-plug-ws-urldata-mqtt-plug-usernamedata-mqtt-plug-passworddata-mqtt-plug-client-prefixdata-mqtt-plug-keepalivedata-mqtt-plug-reconnect-ms+10 moreMQTT_Plug_Config/wp-json/mqtt-plug/v1/status/wp-json/mqtt-plug/v1/snapshot[mqtt_plugmqtt_plug_live_viewermqtt_plug_observer_viewer