
Multisite Tos Security & Risk Analysis
wordpress.org/plugins/multisite-tosThis plugin adds a TOS (Terms of Service) field on the multisite signup form. (Such as wordpress.com TOS field)
Is Multisite Tos Safe to Use in 2026?
Generally Safe
Score 85/100Multisite Tos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multisite-tos plugin version 1.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface, dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant strength. Taint analysis also shows no identified vulnerabilities, indicating a clean codebase in this regard. The plugin demonstrates good practice by using prepared statements for SQL and includes a capability check. However, the 50% rate of unescaped output is a concern, as it could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before display.
The vulnerability history for this plugin is clean, with no recorded CVEs, which is a positive indicator. This suggests a history of stable and secure development. Despite the absence of critical issues, the incomplete output escaping warrants attention. Overall, multisite-tos v1.1 appears to be a secure plugin with no known critical vulnerabilities and a well-controlled attack surface. The primary area for improvement lies in ensuring all output is properly escaped to mitigate potential XSS risks.
Key Concerns
- 50% of outputs are not properly escaped
Multisite Tos Security Vulnerabilities
Multisite Tos Release Timeline
Multisite Tos Code Analysis
Output Escaping
Multisite Tos Attack Surface
WordPress Hooks 5
Maintenance & Trust
Multisite Tos Maintenance & Trust
Maintenance Signals
Community Trust
Multisite Tos Alternatives
Terms of Service & Privacy Policy Generator
terms-of-service-and-privacy-policy
Generates "Terms Of Service" and "Privacy Policy" texts based on your information using shortcodes.
Policy Highlights: Focus on Vital Keywords
weareprivacy
Auto highlight important keywords on any privacy policy or terms of service so users can quickly find and understand critical sections.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
Multisite Tos Developer Profile
9 plugins · 20K total installs
How We Detect Multisite Tos
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ms-toserror