MUDRAVA RUM Security & Risk Analysis

wordpress.org/plugins/mudrava-rum

Real User Monitoring (RUM) plugin for WordPress that tracks TTFB, LCP, server generation time, and other performance metrics from real visitors.

0 active installs v0.2.0 PHP 7.4+ WP 6.2+ Updated Apr 1, 2026
lcpmonitoringperformancerumweb-vitals
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MUDRAVA RUM Safe to Use in 2026?

Generally Safe

Score 100/100

MUDRAVA RUM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "mudrava-rum" plugin v0.2.0 demonstrates an excellent security posture based on the provided static analysis. The absence of any identified dangerous functions, file operations, or external HTTP requests is highly commendable. Furthermore, the plugin fully utilizes prepared statements for all SQL queries and properly escapes all output, indicating a strong defense against common injection and cross-site scripting vulnerabilities. The presence of nonce and capability checks on entry points, coupled with a very small and seemingly protected attack surface (zero unprotected AJAX handlers, REST API routes, shortcodes, or cron events), suggests a well-designed and securely implemented plugin.

The vulnerability history also reflects this strong security. With zero recorded CVEs, and no history of critical, high, or even medium vulnerabilities, the plugin appears to have a track record of stability and security. The lack of any common vulnerability types further reinforces this. The taint analysis revealing no unsanitized paths, critical, or high severity flows is another positive indicator.

In conclusion, the "mudrava-rum" plugin v0.2.0 presents a very low-risk profile. Its adherence to secure coding practices in database interactions and output handling, combined with a minimal and protected attack surface, makes it a secure option. The plugin's clean vulnerability history further solidifies its robust security. There are no immediate concerns or deductions based on the provided data.

Vulnerabilities
None known

MUDRAVA RUM Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MUDRAVA RUM Release Timeline

v0.2.0Current
Code Analysis
Analyzed Apr 16, 2026

MUDRAVA RUM Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
30 prepared
Unescaped Output
0
89 escaped
Nonce Checks
2
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared30 total queries

Output Escaping

100% escaped89 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
render_settings (includes/class-mdvrm-admin.php:168)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MUDRAVA RUM Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuincludes/class-mdvrm-admin.php:37
actionadmin_enqueue_scriptsincludes/class-mdvrm-admin.php:38
actionwp_enqueue_scriptsincludes/class-mdvrm-collector.php:37
actionwp_footerincludes/class-mdvrm-collector.php:38
actioninitincludes/class-mdvrm-plugin.php:89
actionadmin_initincludes/class-mdvrm-plugin.php:101
actioninitincludes/class-mdvrm-reports.php:42
filtercron_schedulesincludes/class-mdvrm-reports.php:51
actionrest_api_initincludes/class-mdvrm-rest.php:42
actionplugins_loadedmudrava-rum.php:34
Maintenance & Trust

MUDRAVA RUM Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 1, 2026
PHP min version7.4
Downloads71

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

MUDRAVA RUM Developer Profile

MUDRAVA

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MUDRAVA RUM

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mudrava-rum/assets/admin/mdvrm-admin.css/wp-content/plugins/mudrava-rum/assets/admin/mdvrm-admin.js
Script Paths
/wp-content/plugins/mudrava-rum/assets/admin/mdvrm-admin.js
Version Parameters
mdvrm-admin.css?ver=mdvrm-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
mdvrm-wrapmdvrm-headermdvrm-header-infomdvrm-actionsmdvrm-info-cardsmdvrm-card-metricmdvrm-goalmdvrm-live-log+3 more
Data Attributes
data-preload
JS Globals
MDVRMAdminSettings
REST Endpoints
/wp-json/mudrava-rum/v1/logs/wp-json/mudrava-rum/v1/stats/wp-json/mudrava-rum/v1/send-report
FAQ

Frequently Asked Questions about MUDRAVA RUM