Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress Security & Risk Analysis

wordpress.org/plugins/plugins-on-steroids

Powerful Plugin Management Solution for WordPress

400 active installs v4.4.1 PHP 7.4+ WP 5.0+ Updated Jan 7, 2026
backupbookmarkmanagerpagespeedsecurity
98
A · Safe
CVEs total2
Unpatched0
Last CVEApr 9, 2025
Safety Verdict

Is Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress Safe to Use in 2026?

Generally Safe

Score 98/100

Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Apr 9, 2025Updated 2mo ago
Risk Assessment

The plugin "plugins-on-steroids" v4.4.1 exhibits a mixed security posture. While the static analysis shows a good number of protected entry points and a lack of critical or high-severity taint flows, there are significant concerns regarding its handling of database queries and output sanitization. All detected SQL queries are not using prepared statements, posing a substantial risk for SQL injection vulnerabilities, especially given the presence of 12 file operations which could potentially be manipulated. The limited number of capability checks (7) compared to the number of AJAX handlers (18) also suggests potential authorization weaknesses if not all AJAX handlers are adequately protected by other means not fully captured by these metrics.

The vulnerability history reveals a past pattern of "Missing Authorization" vulnerabilities and two medium-severity CVEs, one of which was recently disclosed in April 2025. Although currently unpatched CVEs are zero, the historical trend of authorization issues and the fact that SQL queries lack prepared statements are key areas of concern. The proper escaping of outputs is also a weakness, with 31% of outputs not being properly escaped, which can lead to cross-site scripting (XSS) vulnerabilities. Despite a relatively clean taint analysis and a protected attack surface in this version, these underlying code quality issues and historical trends warrant caution.

Key Concerns

  • SQL queries without prepared statements
  • Significant portion of outputs not properly escaped
  • Medium severity CVEs in vulnerability history
  • Historical 'Missing Authorization' vulnerabilities
Vulnerabilities
2

Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-32542medium · 4.3Missing Authorization

Eazy Plugin Manager <= 4.3.0 - Missing Authorization

Apr 9, 2025 Patched in 4.4.0 (275d)
CVE-2023-51482medium · 4.3Missing Authorization

Eazy Plugin Manager <= 4.1.2 - Missing Authorization via update_options

Dec 27, 2023 Patched in 4.1.3 (27d)
Code Analysis
Analyzed Mar 16, 2026

Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
21
47 escaped
Nonce Checks
25
Capability Checks
7
File Operations
12
External Requests
5
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries

Output Escaping

69% escaped68 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
pos_plugin_download_action (plugins-on-steroids.php:151)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress Attack Surface

Entry Points18
Unprotected0

AJAX Handlers 18

authwp_ajax_pos_installplugins-on-steroids.php:440
authwp_ajax_pos_version_switchplugins-on-steroids.php:441
authwp_ajax_pos_lockplugins-on-steroids.php:442
authwp_ajax_pos_lock_listplugins-on-steroids.php:443
authwp_ajax_pos_update_optionplugins-on-steroids.php:445
authwp_ajax_pos_get_optionplugins-on-steroids.php:446
authwp_ajax_pos_update_tokenplugins-on-steroids.php:447
authwp_ajax_pos_update_dissmiss_noticeplugins-on-steroids.php:448
authwp_ajax_pos_bookmarksplugins-on-steroids.php:449
authwp_ajax_pos_message_modalplugins-on-steroids.php:450
authwp_ajax_pos_confirmation_modalplugins-on-steroids.php:451
authwp_ajax_pos_vault_modal_freeplugins-on-steroids.php:452
authwp_ajax_pos_load_ps_version_modalplugins-on-steroids.php:453
authwp_ajax_pos_historiesplugins-on-steroids.php:454
authwp_ajax_pos_postsplugins-on-steroids.php:455
authwp_ajax_pos_pagesplugins-on-steroids.php:456
authwp_ajax_pos_x256plugins-on-steroids.php:457
authwp_ajax_pos_bloomplugins-on-steroids.php:458
WordPress Hooks 14
actioninitplugins-on-steroids.php:57
actionadmin_initplugins-on-steroids.php:58
actionadmin_noticesplugins-on-steroids.php:73
filterplugins_listplugins-on-steroids.php:429
actionadmin_enqueue_scriptsplugins-on-steroids.php:431
actionadmin_headplugins-on-steroids.php:432
actionadmin_menuplugins-on-steroids.php:434
actionpre_current_active_pluginsplugins-on-steroids.php:437
actiondelete_pluginplugins-on-steroids.php:478
actionactivate_pluginplugins-on-steroids.php:479
actiondeactivate_pluginplugins-on-steroids.php:480
actionupgrader_process_completeplugins-on-steroids.php:481
filterupgrader_pre_downloadplugins-on-steroids.php:488
actionadmin_noticesplugins-on-steroids.php:1257
Maintenance & Trust

Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 7, 2026
PHP min version7.4
Downloads18K

Community Trust

Rating100/100
Number of ratings6
Active installs400
Developer Profile

Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress Developer Profile

EazyPlugins

2 plugins · 410 total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
151 days
View full developer profile
Detection Fingerprints

How We Detect Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/plugins-on-steroids/css/bootstrap.min.css/wp-content/plugins/plugins-on-steroids/css/pos-admin.css/wp-content/plugins/plugins-on-steroids/css/pos-dashboard.css/wp-content/plugins/plugins-on-steroids/css/pos-settings.css/wp-content/plugins/plugins-on-steroids/css/select2.min.css/wp-content/plugins/plugins-on-steroids/js/bootstrap.min.js/wp-content/plugins/plugins-on-steroids/js/jquery.validate.min.js/wp-content/plugins/plugins-on-steroids/js/pos-admin.js+4 more
Script Paths
/wp-content/plugins/plugins-on-steroids/js/pos-admin.js/wp-content/plugins/plugins-on-steroids/js/pos-dashboard.js/wp-content/plugins/plugins-on-steroids/js/pos-settings.js
Version Parameters
plugins-on-steroids/css/bootstrap.min.css?ver=plugins-on-steroids/css/pos-admin.css?ver=plugins-on-steroids/css/pos-dashboard.css?ver=plugins-on-steroids/css/pos-settings.css?ver=plugins-on-steroids/css/select2.min.css?ver=plugins-on-steroids/js/bootstrap.min.js?ver=plugins-on-steroids/js/jquery.validate.min.js?ver=plugins-on-steroids/js/pos-admin.js?ver=plugins-on-steroids/js/pos-dashboard.js?ver=plugins-on-steroids/js/pos-settings.js?ver=plugins-on-steroids/js/pos-validation.js?ver=plugins-on-steroids/js/select2.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
pos-noticepos_download-wrappos_download_linkpos_bookmark-wrappos_bookmark_linkpos_vault-wrappos_vault_link
Data Attributes
data-slugdata-folderdata-version
JS Globals
POS_AssetsPOS_PluginsRest_ApiPOS_PATHPOS_URLPOS_API_ENDPOINT+1 more
FAQ

Frequently Asked Questions about Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress