NIX Anti-Spam Light Security & Risk Analysis

wordpress.org/plugins/nix-anti-spam-light

Easy-to-use tool to get rid of spam attacking your website AntiSpamLight is developed to help you to forget about annoying spam bots! No more spam and …

80 active installs v0.0.4 PHP + WP 3.0.1+ Updated Oct 29, 2014
anti-spamanti-spam-botno-captchasecurityspam
35
D · High Risk
CVEs total2
Unpatched2
Last CVESep 22, 2025
Download
Safety Verdict

Is NIX Anti-Spam Light Safe to Use in 2026?

High Risk

Score 35/100

NIX Anti-Spam Light carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.

2 known CVEs 2 unpatched Last CVE: Sep 22, 2025Updated 11yr ago
Risk Assessment

The nix-anti-spam-light plugin v0.0.4 presents a concerning security posture despite its limited attack surface. While it has no apparent direct entry points like AJAX handlers, REST API routes, or shortcodes, the presence of the dangerous `unserialize` function is a significant red flag. This function, when used with untrusted input, can lead to deserialization vulnerabilities, as indicated by the taint analysis showing two flows with unsanitized paths and two high-severity issues. The vulnerability history further amplifies these concerns, with two known CVEs, both currently unpatched, including one critical vulnerability often associated with deserialization of untrusted data. This pattern suggests a recurring weakness in how the plugin handles potentially malicious input. Although the plugin uses prepared statements for SQL queries and has no external HTTP requests or file operations, the critical lack of output escaping for all 11 identified outputs and the complete absence of nonce and capability checks on any potential, albeit currently hidden, entry points are serious omissions. The plugin's history of critical deserialization vulnerabilities, coupled with the static analysis findings, points to a high risk of exploitation. Users should exercise extreme caution.

Key Concerns

  • Unpatched Critical CVE (2025-09-22)
  • Unpatched Medium CVE (2025-09-22)
  • High Severity Taint Flow (2)
  • Dangerous function: unserialize
  • Output escaping: 0% properly escaped (11 outputs)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
2 published

NIX Anti-Spam Light Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
1

2 total CVEs

CVE-2025-58270medium · 4.3Cross-Site Request Forgery (CSRF)

NIX Anti-Spam Light <= 0.0.4 - Cross-Site Request Forgery

Sep 22, 2025Unpatched
CVE-2024-52432critical · 9.8Deserialization of Untrusted Data

NIX Anti-Spam Light <= 0.0.4 - Unauthenticated PHP Object Injection

Nov 15, 2024Unpatched
Version History

NIX Anti-Spam Light Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

NIX Anti-Spam Light Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$data_A = unserialize(base64_decode($data));nix-antispam-light.php:124

Output Escaping

0% escaped11 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
nfas_pre_comment_approved (nix-antispam-light.php:118)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

NIX Anti-Spam Light Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_noticesmessages.class.php:9
actioncomment_formnix-antispam-light.php:38
filterpre_comment_approvednix-antispam-light.php:39
actionadmin_menunix-antispam-light.php:43
Maintenance & Trust

NIX Anti-Spam Light Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedOct 29, 2014
PHP min version
Downloads6K

Community Trust

Rating74/100
Number of ratings3
Active installs80
Developer Profile

NIX Anti-Spam Light Developer Profile

NIX Solutions Ltd

1 plugin · 80 total installs

49
trust score
Avg Security Score
35/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NIX Anti-Spam Light

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nix-anti-spam-light/js/main.js/wp-content/plugins/nix-anti-spam-light/css/style.css
Script Paths
/wp-content/plugins/nix-anti-spam-light/js/main.js
Version Parameters
nix-anti-spam-light/js/main.js?ver=nix-anti-spam-light/css/style.css?ver=

HTML / DOM Fingerprints

Data Attributes
namevalue
JS Globals
NFASL_Antispam_Light
FAQ

Frequently Asked Questions about NIX Anti-Spam Light