Ozh' Spam Magnet Checker Security & Risk Analysis

wordpress.org/plugins/ozh-spam-magnet-checker

Identify posts spammers find the most attractive.

10 active installs v1.0.1 PHP + WP 3.0+ Updated Sep 27, 2010
magnetozhspam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ozh' Spam Magnet Checker Safe to Use in 2026?

Generally Safe

Score 85/100

Ozh' Spam Magnet Checker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The ozh-spam-magnet-checker plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The code demonstrates good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks for its single AJAX entry point. Notably, there are no recorded CVEs, and the taint analysis found no unsanitized paths, indicating a lack of critical vulnerabilities within the analyzed code.

While the plugin appears secure in its current version, a minor concern arises from the output escaping. With 75% of outputs properly escaped, there is a small possibility of unescaped output, which could theoretically lead to a low-severity cross-site scripting (XSS) vulnerability if the unescaped data is user-controlled and rendered directly in the browser. However, given the absence of recorded vulnerabilities and the limited attack surface, this risk is minimal. Overall, the plugin is well-developed from a security perspective, with a strong emphasis on preventing common attack vectors.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

Ozh' Spam Magnet Checker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ozh' Spam Magnet Checker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
1
3 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

75% escaped4 total outputs
Attack Surface

Ozh' Spam Magnet Checker Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_ozh_smc_closeplugin.php:17
WordPress Hooks 1
actionadmin_menuplugin.php:16
Maintenance & Trust

Ozh' Spam Magnet Checker Maintenance & Trust

Maintenance Signals

WordPress version tested9.9
Last updatedSep 27, 2010
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Ozh' Spam Magnet Checker Developer Profile

Ozh

27 plugins · 5K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ozh' Spam Magnet Checker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/ozh-spam-magnet-checker/ozh_smc_admin.js

HTML / DOM Fingerprints

CSS Classes
ozh_smc_close
Data Attributes
data-id
JS Globals
ozh_smc_close
FAQ

Frequently Asked Questions about Ozh' Spam Magnet Checker