
My WP A/B Testing Security & Risk Analysis
wordpress.org/plugins/my-wp-ab-testingAn easy way to set up A/B Testing Campaigns using Gutenberg blocks, and to get the conversion rates for each variation.
Is My WP A/B Testing Safe to Use in 2026?
Generally Safe
Score 100/100My WP A/B Testing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "my-wp-ab-testing" plugin v0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having a clean vulnerability history with no recorded CVEs. The presence of nonce and capability checks, albeit limited, is also a good sign. However, significant concerns arise from the attack surface. With 3 total entry points, 2 of which are unprotected AJAX handlers, there's a substantial risk of unauthorized access and potential manipulation. The output escaping is also a concern, with 37% of outputs not being properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities. The lack of any taint analysis results, while technically indicating no identified flows, might also suggest limited static analysis depth or an insufficient number of flows analyzed to be fully conclusive.
In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the unprotected AJAX endpoints represent a critical security weakness that could be exploited. The partially unescaped output further exacerbates this risk. The clean vulnerability history is positive but does not negate the immediate risks identified in the code analysis. Addressing the unprotected AJAX handlers and improving output escaping should be immediate priorities.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
My WP A/B Testing Security Vulnerabilities
My WP A/B Testing Code Analysis
Output Escaping
My WP A/B Testing Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
My WP A/B Testing Maintenance & Trust
Maintenance Signals
Community Trust
My WP A/B Testing Alternatives
No alternatives data available yet.
My WP A/B Testing Developer Profile
24 plugins · 64K total installs
How We Detect My WP A/B Testing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-wp-ab-testing/js/reblexab-stat.js/wp-content/plugins/my-wp-ab-testing/css/reblexab-admin.css/wp-content/plugins/my-wp-ab-testing/vendor/chart/chart.min.js/wp-content/plugins/my-wp-ab-testing/js/reblexab-admin.js/wp-content/plugins/my-wp-ab-testing/js/reblexab-stat.js/wp-content/plugins/my-wp-ab-testing/vendor/chart/chart.min.js/wp-content/plugins/my-wp-ab-testing/js/reblexab-admin.jsmy-wp-ab-testing/js/reblexab-stat.js?ver=my-wp-ab-testing/css/reblexab-admin.css?ver=my-wp-ab-testing/vendor/chart/chart.min.js?ver=my-wp-ab-testing/js/reblexab-admin.js?ver=HTML / DOM Fingerprints
reblexab-admindata-reblexab-block-a-target-selectordata-reblexab-block-b-target-selectorreblexab_localizereblexab_ajax_url/wp-json/my-wp-ab-testing/