Ozh' Who Sees Ads Security & Risk Analysis

wordpress.org/plugins/ozh-who-sees-ads

Manage your ads. Define under what condition they will show (visitor from search engine, old post..). Make more money.

100 active installs v2.0.5 PHP + WP 2.5+ Updated Dec 22, 2014
adsadsenseaffiliateyahoo-publisherypn
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ozh' Who Sees Ads Safe to Use in 2026?

Generally Safe

Score 85/100

Ozh' Who Sees Ads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The ozh-who-sees-ads plugin v2.0.5 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs and the fact that all SQL queries utilize prepared statements are significant strengths. Furthermore, the plugin's attack surface is currently zero, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. This indicates a deliberate effort by the developer to minimize potential entry points for attackers.

However, the static analysis does reveal a critical concern: the presence of the `create_function` dangerous function. This function is known to be highly susceptible to code injection vulnerabilities if user-supplied data is not strictly controlled and sanitized before being passed to it. While there are no observed taint flows or unescaped outputs reported in this specific analysis, the potential for exploitation via `create_function` remains a significant risk. The low percentage of properly escaped outputs (15%) is also a concern, as it suggests that a large portion of the plugin's output may be vulnerable to Cross-Site Scripting (XSS) attacks, even if no specific instances were flagged in this particular analysis.

Key Concerns

  • Presence of dangerous function: create_function
  • Low percentage of properly escaped output
Vulnerabilities
None known

Ozh' Who Sees Ads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ozh' Who Sees Ads Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
46
8 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functioncreate_function(wp_ozh_whoseesads.php:863

Output Escaping

15% escaped54 total outputs
Attack Surface

Ozh' Who Sees Ads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwidgets_initwp_ozh_whoseesads.php:852
actionwidget_textwp_ozh_whoseesads.php:853
actionplugins_loadedwp_ozh_whoseesads.php:891
actionplugins_loadedwp_ozh_whoseesads.php:892
actionadmin_menuwp_ozh_whoseesads.php:893
actionthe_contentwp_ozh_whoseesads.php:894
actionexplain_nonce_ozh-wsawp_ozh_whoseesads_admin.php:1634
actionadmin_footerwp_ozh_whoseesads_admin.php:1635
Maintenance & Trust

Ozh' Who Sees Ads Maintenance & Trust

Maintenance Signals

WordPress version tested9.9
Last updatedDec 22, 2014
PHP min version
Downloads76K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Ozh' Who Sees Ads Developer Profile

Ozh

27 plugins · 5K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ozh' Who Sees Ads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Ozh' Who Sees Ads