Demo Data Creator Security & Risk Analysis

wordpress.org/plugins/multilingual-demo-data-creator

Multilingual Demo Data Creator enables you to create demo users, blogs, posts, comments and blogroll links in different languages for a Wordpress site …

10 active installs v0.1 PHP + WP 2.7+ Updated Unknown
datademomultilingualwpmu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Demo Data Creator Safe to Use in 2026?

Generally Safe

Score 100/100

Demo Data Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "multilingual-demo-data-creator" plugin version 0.1 exhibits a mixed security posture. On the positive side, there are no known CVEs associated with the plugin, and the static analysis found no dangerous functions or external HTTP requests. The majority of SQL queries utilize prepared statements, which is a good practice. However, several significant concerns emerge from the analysis. The plugin lacks any nonce checks or capability checks, which is a major vulnerability. Furthermore, the taint analysis reveals multiple flows with unsanitized paths, three of which are flagged as high severity. The extremely low percentage of properly escaped output (9%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. File operations are also present without clear security controls.

While the plugin has no recorded vulnerability history, this may be due to its low version number and potentially limited usage. The absence of auth checks for AJAX handlers, REST API routes, shortcodes, and cron events, combined with the critical taint flows and poor output escaping, paints a concerning picture. The 5 unsanitized path flows, with 3 of high severity, are particularly alarming and suggest potential path traversal or file inclusion vulnerabilities. The complete lack of nonce and capability checks leaves the plugin's functionalities open to unauthorized access and manipulation.

Key Concerns

  • High severity unsanitized taint flows
  • Unescaped output (9% properly escaped)
  • No nonce checks
  • No capability checks
  • Unsanitized path flows (5 total)
  • File operations present without context
  • No AJAX auth checks
  • No REST API permission callbacks
Vulnerabilities
None known

Demo Data Creator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Demo Data Creator Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
21 prepared
Unescaped Output
40
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

84% prepared25 total queries

Output Escaping

9% escaped44 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
wmdd_create_users (demodata.php:288)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Demo Data Creator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitdemodata.php:36
actionadmin_menudemodata.php:41
actionadmin_menudemodata.php:68
actionadmin_headdemodata.php:161
actionadmin_headdemodata.php:162
filterupload_dirdemodata.php:1482
filterupload_mimesdemodata.php:1520
filterlocaledemodata.php:1554
Maintenance & Trust

Demo Data Creator Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedUnknown
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Demo Data Creator Developer Profile

Ayebare Mucunguzi Brooks

8 plugins · 340 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Demo Data Creator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multilingual-demo-data-creator/style.css/wp-content/plugins/multilingual-demo-data-creator/wmdd.js
Script Paths
/wp-content/plugins/multilingual-demo-data-creator/wmdd.js
Version Parameters
multilingual-demo-data-creator/style.css?ver=multilingual-demo-data-creator/wmdd.js?ver=

HTML / DOM Fingerprints

CSS Classes
wmddpendingspinnerpromo
Data Attributes
id="wmdd_results"class="wmdd"id="delete"outputid="delete"form
JS Globals
jQuery
FAQ

Frequently Asked Questions about Demo Data Creator