Multisite Plugin Manager Security & Risk Analysis

wordpress.org/plugins/multisite-plugin-manager

The essential plugin for every multisite install! Manage plugin access permissions across your entire multisite network.

200 active installs v3.1.6 PHP + WP 3.7.3+ Updated Aug 18, 2020
multisitepluginswpmu
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multisite Plugin Manager Safe to Use in 2026?

Generally Safe

Score 85/100

Multisite Plugin Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The multisite-plugin-manager v3.1.6 plugin exhibits a generally good security posture with no known historical vulnerabilities or identified critical or high-severity issues in the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the plugin avoids dangerous functions, file operations, and external HTTP requests, which are common sources of vulnerabilities.

However, there are some areas for concern. The static analysis revealed a concerning 4 out of 4 analyzed taint flows with unsanitized paths, although these did not reach a critical or high severity. This indicates a potential for sensitive data to be processed without adequate sanitization, which could be exploited under specific conditions, especially if combined with other weaknesses. Additionally, a low rate of output escaping (29%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is displayed without proper encoding. The complete lack of nonce checks and limited capability checks (2) on entry points is also a significant oversight, as it leaves potential avenues for unauthorized actions or data manipulation if any unintended entry points are discovered or introduced.

In conclusion, while the plugin benefits from a small attack surface and a clean vulnerability history, the presence of unsanitized paths in taint flows and poor output escaping are notable weaknesses. The absence of nonce checks and limited capability checks further compounds these risks. While not currently posing an immediate critical threat based on the provided data, these issues warrant attention to improve the overall security robustness of the plugin and prevent potential future vulnerabilities.

Key Concerns

  • Unsanitized paths in taint flows (4/4)
  • Low output escaping rate (29%)
  • No nonce checks
  • Limited capability checks (2)
  • SQL queries not using prepared statements (33%)
Vulnerabilities
None known

Multisite Plugin Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Multisite Plugin Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
4 prepared
Unescaped Output
24
10 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

67% prepared6 total queries

Output Escaping

29% escaped34 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
process_form (plugin-manager.php:201)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Multisite Plugin Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionnetwork_admin_menuplugin-manager.php:33
actionwpmu_new_blogplugin-manager.php:34
filterall_pluginsplugin-manager.php:37
filterplugin_action_linksplugin-manager.php:40
actionadmin_noticesplugin-manager.php:42
actionplugins_loadedplugin-manager.php:43
actionwpmueditblogactionplugin-manager.php:46
actionwpmu_update_blog_optionsplugin-manager.php:47
filterplugin_row_metaplugin-manager.php:49
actionadmin_initplugin-manager.php:50
actionnetwork_admin_menutrunk\plugin-manager.php:33
actionwpmu_new_blogtrunk\plugin-manager.php:34
filterall_pluginstrunk\plugin-manager.php:37
filterplugin_action_linkstrunk\plugin-manager.php:40
actionadmin_noticestrunk\plugin-manager.php:42
actionplugins_loadedtrunk\plugin-manager.php:43
actionwpmueditblogactiontrunk\plugin-manager.php:46
actionwpmu_update_blog_optionstrunk\plugin-manager.php:47
filterplugin_row_metatrunk\plugin-manager.php:49
actionadmin_inittrunk\plugin-manager.php:50
Maintenance & Trust

Multisite Plugin Manager Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 18, 2020
PHP min version
Downloads108K

Community Trust

Rating84/100
Number of ratings23
Active installs200
Developer Profile

Multisite Plugin Manager Developer Profile

Aaron Edwards

4 plugins · 520 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Multisite Plugin Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/multisite-plugin-manager/css/style.css
Script Paths
/wp-content/plugins/multisite-plugin-manager/js/pm-admin.js
Version Parameters
multisite-plugin-manager/css/style.css?ver=multisite-plugin-manager/js/pm-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
donate-message
Data Attributes
data-plugin-manager
JS Globals
plugin_manager_params
FAQ

Frequently Asked Questions about Multisite Plugin Manager