
Multisite Tos Security & Risk Analysis
wordpress.org/plugins/multisite-tosThis plugin adds a TOS (Terms of Service) field on the multisite signup form. (Such as wordpress.com TOS field)
Is Multisite Tos Safe to Use in 2026?
Generally Safe
Score 85/100Multisite Tos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multisite-tos plugin version 1.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface, dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant strength. Taint analysis also shows no identified vulnerabilities, indicating a clean codebase in this regard. The plugin demonstrates good practice by using prepared statements for SQL and includes a capability check. However, the 50% rate of unescaped output is a concern, as it could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before display.
The vulnerability history for this plugin is clean, with no recorded CVEs, which is a positive indicator. This suggests a history of stable and secure development. Despite the absence of critical issues, the incomplete output escaping warrants attention. Overall, multisite-tos v1.1 appears to be a secure plugin with no known critical vulnerabilities and a well-controlled attack surface. The primary area for improvement lies in ensuring all output is properly escaped to mitigate potential XSS risks.
Key Concerns
- 50% of outputs are not properly escaped
Multisite Tos Security Vulnerabilities
Multisite Tos Code Analysis
Output Escaping
Multisite Tos Attack Surface
WordPress Hooks 5
Maintenance & Trust
Multisite Tos Maintenance & Trust
Maintenance Signals
Community Trust
Multisite Tos Alternatives
Terms of Service & Privacy Policy Generator
terms-of-service-and-privacy-policy
Generates "Terms Of Service" and "Privacy Policy" texts based on your information using shortcodes.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
WPZOOM Social Feed Widget & Block
instagram-widget-by-wpzoom
Instagram feed plugin for WordPress: Display your Instagram photos, videos & reels. Easy setup with Gutenberg block, widget, shortcode & Elementor
Multisite Tos Developer Profile
9 plugins · 20K total installs
How We Detect Multisite Tos
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ms-toserror