
Petje.af Security & Risk Analysis
wordpress.org/plugins/petje-afThe official Petje.af WordPress to connect your WordPress website with your Petje.af page.
Is Petje.af Safe to Use in 2026?
Use With Caution
Score 63/100Petje.af has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin "petje-af" v2.1.8 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL query handling, exclusively using prepared statements, and has no recorded vulnerabilities or known CVEs, suggesting a history of stable and secure development. The absence of dangerous functions, file operations, and critical taint analysis findings further contributes to this positive outlook.
However, significant concerns arise from the attack surface. A notable proportion of the entry points, specifically 6 out of 10 (60%), are unprotected by authentication checks. This includes all 6 AJAX handlers. While capability checks are present, their absence on these critical AJAX endpoints leaves them vulnerable to unauthorized access and potential exploitation if they perform sensitive actions or reveal protected information. The low percentage of properly escaped output (38%) is also a concern, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being displayed.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the high number of unprotected AJAX handlers and insufficient output escaping represent immediate and actionable security risks that should be addressed to improve its overall security posture.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
Petje.af Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Petje.af <= 2.1.8 - Cross-Site Request Forgery to Account Deletion via 'petjeaf_disconnect' AJAX Action
Petje.af Code Analysis
Output Escaping
Petje.af Attack Surface
AJAX Handlers 6
Shortcodes 4
WordPress Hooks 17
Maintenance & Trust
Petje.af Maintenance & Trust
Maintenance Signals
Community Trust
Petje.af Alternatives
Members – Membership & User Role Editor Plugin
members
The best WordPress membership and user role editor plugin. User Roles & Capabilities editor helps you restrict content in just a few clicks.
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
Setup paid membership, accept payment, sell subscription & digital product, paywall, create login & registration form, user profile & member directory
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
WP-Members Membership Plugin
wp-members
The original WordPress membership plugin with content restriction, user login, custom registration fields, user profiles, and more.
Petje.af Developer Profile
1 plugin · 10 total installs
How We Detect Petje.af
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/petje-af/css/petje-af-admin.css/wp-content/plugins/petje-af/js/admin.js/wp-content/plugins/petje-af/js/admin.jspetje-af/css/petje-af-admin.css?ver=petje-af/js/admin.js?ver=HTML / DOM Fingerprints
data-petjeaf-client-iddata-petjeaf-client-secretdata-petjeaf-page-iddata-petjeaf-site-protection-plandata-petjeaf-ignore-access-settings-for-adminpetjeaf_vars