
Quantely Activity Security & Risk Analysis
wordpress.org/plugins/quantely-activitySee what is really happening on your WordPress website.
Is Quantely Activity Safe to Use in 2026?
Generally Safe
Score 100/100Quantely Activity has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "quantely-activity" plugin v1.1.4 exhibits a generally good security posture, largely due to its strong adherence to secure coding practices. The plugin exclusively uses prepared statements for all its SQL queries, a critical measure against SQL injection vulnerabilities. Furthermore, it demonstrates excellent output escaping, with 97% of outputs properly handled, significantly reducing the risk of cross-site scripting (XSS) attacks. The absence of file operations and external HTTP requests further limits potential attack vectors. The plugin also incorporates a reasonable number of nonce and capability checks, indicating an awareness of authentication and authorization best practices.
However, a notable concern arises from the presence of one unprotected REST API route. This single entry point, lacking permission callbacks, could potentially be exploited by unauthenticated users to interact with sensitive plugin functionality. While the static analysis did not reveal any critical or high-severity taint flows, and there is no recorded vulnerability history, this unprotected endpoint represents a tangible security weakness that could be leveraged by attackers. The limited attack surface overall is positive, but the unprotected entry point is a specific area requiring attention.
In conclusion, the "quantely-activity" plugin has many strengths, particularly its robust handling of SQL and output sanitization. The lack of historical vulnerabilities further suggests a commitment to security. Nevertheless, the unprotected REST API route is a significant enough concern to warrant a deduction from its otherwise strong security score. Addressing this single unprotected entry point would significantly improve the plugin's overall security.
Key Concerns
- Unprotected REST API route without permission callbacks
Quantely Activity Security Vulnerabilities
Quantely Activity Release Timeline
Quantely Activity Code Analysis
SQL Query Safety
Output Escaping
Quantely Activity Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 8
Maintenance & Trust
Quantely Activity Maintenance & Trust
Maintenance Signals
Community Trust
Quantely Activity Alternatives
Post Views Counter
post-views-counter
Post Views Counter allows you to collect and display how many times a post, page, or other content has been viewed in a simple, fast and reliable way.
Statify
statify
Visitor statistics for WordPress with focus on data protection, transparency and clarity. Perfect as a widget in your WordPress Dashboard.
Pure Chat – Live Chat & More!
pure-chat
Pure Chat provides a Live Chat plugin with Unlimited Chats for your website!
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
logtivity
Logtivity is the activity log service for WordPress admins. Logtivity is a unified activity log platform that tracks activity and errors across all yo …
WP Online Active Users
online-active-users
WP Online Active Users is a lightweight, powerful plugin to monitor and display how many users are currently online active on your WordPress website.
Quantely Activity Developer Profile
1 plugin · 0 total installs
How We Detect Quantely Activity
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quantely-activity/assets/admin.css/wp-content/plugins/quantely-activity/assets/admin.jsquantely-activity/assets/admin.css?ver=quantely-activity/assets/admin.js?ver=HTML / DOM Fingerprints
qmon-titleqmon-subtitleqmon-versionqmon-tabsqmon-boxdata-qmon-data-retentiondata-qmon-data-visit-cookie-enableddata-qmon-data-server-collector-enabledqmonAdmin