Multisite Plugin Controller Security & Risk Analysis

wordpress.org/plugins/multisite-plugin-controller

Enable plugins for selected blogs only on multisite websites (similar to theme functionality)

0 active installs v1.0.0 PHP + WP 3.9.2+ Updated Feb 4, 2021
multisite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Multisite Plugin Controller Safe to Use in 2026?

Generally Safe

Score 85/100

Multisite Plugin Controller has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'multisite-plugin-controller' v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, file operations, and external HTTP requests. All SQL queries are prepared, and there is no recorded vulnerability history, suggesting a generally stable and well-maintained codebase. The static analysis indicates a very small attack surface, with zero identified entry points that lack authentication or permission checks.

However, there are significant areas of concern that temper the otherwise positive findings. The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this specific analysis, represent potential vulnerabilities if exploited. Furthermore, a substantial portion (58%) of output escaping is not properly handled. While the absence of nonce and capability checks on the identified entry points is mitigated by the fact that there are no such entry points, it highlights a lack of defensive programming in general. The plugin's current version and lack of recorded vulnerabilities are good, but the unescaped output and unsanitized paths warrant attention for future improvements and ongoing vigilance.

Key Concerns

  • Unsanitized paths in taint flows
  • Insufficient output escaping (58% unescaped)
Vulnerabilities
None known

Multisite Plugin Controller Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Multisite Plugin Controller Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Multisite Plugin Controller Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

42% escaped12 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
mpcHandleAdminPage (multisite-plugin-controller.php:87)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Multisite Plugin Controller Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitmultisite-plugin-controller.php:30
filternetwork_edit_site_nav_linksmultisite-plugin-controller.php:46
actionnetwork_admin_menumultisite-plugin-controller.php:64
actionadmin_headmultisite-plugin-controller.php:79
actionpre_current_active_pluginsmultisite-plugin-controller.php:265
Maintenance & Trust

Multisite Plugin Controller Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedFeb 4, 2021
PHP min version
Downloads885

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Multisite Plugin Controller Developer Profile

babo2015

2 plugins · 200 total installs

92
trust score
Avg Security Score
88/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Multisite Plugin Controller

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multisite-plugin-controller/css/mpc-backend.css/wp-content/plugins/multisite-plugin-controller/js/mpc-backend.js
Script Paths
/wp-content/plugins/multisite-plugin-controller/js/mpc-backend.js
Version Parameters
multisite-plugin-controller/css/mpc-backend.css?ver=multisite-plugin-controller/js/mpc-backend.js?ver=

HTML / DOM Fingerprints

CSS Classes
mpc-backend-wrapper
HTML Comments
<!-- mpc --><!-- Some CSS to hide the link to our custom submenu page --><!-- mpc-check --><!-- Network enabled plugins are not shown on this screen. -->+18 more
Data Attributes
data-blog-iddata-plugin-slug
JS Globals
mpc_backend_vars
FAQ

Frequently Asked Questions about Multisite Plugin Controller