
Nashaat Activity Log Security & Risk Analysis
wordpress.org/plugins/nashaat-activity-logLog site editors activity
Is Nashaat Activity Log Safe to Use in 2026?
Generally Safe
Score 100/100Nashaat Activity Log has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'nashaat-activity-log' plugin v1.2.4 exhibits a mixed security posture. On the positive side, it has a clean vulnerability history with no known CVEs, and the code generally follows good practices like using prepared statements for most SQL queries and properly escaping a high percentage of outputs. The absence of external HTTP requests and bundled libraries further reduces potential attack vectors. However, concerns arise from the static analysis. A significant weakness is the presence of one AJAX handler that lacks authentication checks, creating an unprotected entry point. Furthermore, the taint analysis revealed one flow with an unsanitized path, which, although not classified as critical or high severity, still represents a potential avenue for exploitation if an attacker can control the input leading to that path. The limited number of flows analyzed by taint analysis might also mean that other potentially problematic flows were not identified.
Key Concerns
- Unprotected AJAX handler
- Taint flow with unsanitized path
- SQL queries not using prepared statements (2/5)
Nashaat Activity Log Security Vulnerabilities
Nashaat Activity Log Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Nashaat Activity Log Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
Nashaat Activity Log Maintenance & Trust
Maintenance Signals
Community Trust
Nashaat Activity Log Alternatives
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
logtivity
Logtivity is the activity log service for WordPress admins. Logtivity is a unified activity log platform that tracks activity and errors across all yo …
Simple History – Track, Log, and Audit WordPress Changes
simple-history
Track changes and user activities on your WordPress site. See who created a page, uploaded an attachment, and more, for a complete audit trail.
WP Activity Log
wp-security-audit-log
The #1 user-rated activity log plugin for event logging, activity monitoring and change tracking.
Honeypot Toolkit
honeypot-toolkit
Automatically insert Project Honeypot links into your pages and block IP addresses that are listed on various block lists you can choose from.
Adminify Activity Logs
adminify-activity-logs
Track WordPress dashboard activities with this free plugin. Monitor user actions, filter by time, role for complete site security and accountability
Nashaat Activity Log Developer Profile
4 plugins · 1K total installs
How We Detect Nashaat Activity Log
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nashaat-activity-log/css/main-style.css/wp-content/plugins/nashaat-activity-log/js/main-script.js/wp-content/plugins/nashaat-activity-log/css/settings-style.css/wp-content/plugins/nashaat-activity-log/js/settings-script.jsnashaat-activity-log/css/main-style.css?ver=nashaat-activity-log/js/main-script.js?ver=nashaat-activity-log/css/settings-style.css?ver=nashaat-activity-log/js/settings-script.js?ver=HTML / DOM Fingerprints
nashaat-log-filternashaat-log-table<!-- WooCommerce --><!-- Gravity --><!-- User switching --><!-- WP Crontrol -->+2 moredata:image/svg+xml;base64,vars.nashaat_nonce