MQTT-Plug Security & Risk Analysis

wordpress.org/plugins/mqtt-plug

Real-time MQTT dashboards inside WordPress. Connect securely over WebSocket (WS/WSS) and visualize live IoT data, logs, and events.

0 active installs v1.0 PHP 7.4+ WP 6.0+ Updated Feb 5, 2026
dashboardsiotmqttrealtimewebsocket
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MQTT-Plug Safe to Use in 2026?

Generally Safe

Score 100/100

MQTT-Plug has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "mqtt-plug" plugin version 1.0 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive sign. The plugin exclusively uses prepared statements for SQL queries, which is a best practice for preventing SQL injection vulnerabilities. Furthermore, the plugin has a strong output escaping rate (87%), indicating an effort to mitigate cross-site scripting (XSS) risks. The capability checks are also present, which is important for authorization.

Key Concerns

  • Missing nonce checks on entry points
  • 13% of outputs are not properly escaped
Vulnerabilities
None known

MQTT-Plug Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

MQTT-Plug Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
163 escaped
Nonce Checks
0
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

87% escaped188 total outputs
Attack Surface

MQTT-Plug Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mqtt_plug] mqtt-plug.php:33
WordPress Hooks 6
actionadmin_menumqtt-plug.php:28
actionadmin_initmqtt-plug.php:29
filterkses_allowed_protocolsmqtt-plug.php:31
actionwp_enqueue_scriptsmqtt-plug.php:32
actionrest_api_initmqtt-plug.php:35
actionwp_footermqtt-plug.php:481
Maintenance & Trust

MQTT-Plug Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 5, 2026
PHP min version7.4
Downloads141

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MQTT-Plug Developer Profile

POTAR

4 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MQTT-Plug

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mqtt-plug/mqtt-plug.css/wp-content/plugins/mqtt-plug/mqtt-plug.js
Script Paths
/wp-content/plugins/mqtt-plug/mqtt-plug.js
Version Parameters
mqtt-plug/mqtt-plug.css?ver=mqtt-plug/mqtt-plug.js?ver=

HTML / DOM Fingerprints

CSS Classes
mqtt-plug-live-viewermqtt-plug-observer-viewer
HTML Comments
MQTT-Plug Live ViewerMQTT-Plug Observer Viewer
Data Attributes
data-mqtt-plug-ws-urldata-mqtt-plug-usernamedata-mqtt-plug-passworddata-mqtt-plug-client-prefixdata-mqtt-plug-keepalivedata-mqtt-plug-reconnect-ms+10 more
JS Globals
MQTT_Plug_Config
REST Endpoints
/wp-json/mqtt-plug/v1/status/wp-json/mqtt-plug/v1/snapshot
Shortcode Output
[mqtt_plugmqtt_plug_live_viewermqtt_plug_observer_viewer
FAQ

Frequently Asked Questions about MQTT-Plug