
SbS Settings Security & Risk Analysis
wordpress.org/plugins/sbs-settingsAll-in-one WordPress & WooCommerce optimization. Modern AJAX toggle UI, completely free.
Is SbS Settings Safe to Use in 2026?
Generally Safe
Score 100/100SbS Settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sbs-settings" v1.0.2 plugin exhibits a concerning security posture primarily due to its extensive unprotected AJAX endpoints. While the code displays strong adherence to secure coding practices like prepared SQL statements and output escaping, the lack of authentication on all 10 identified AJAX handlers presents a significant attack surface. The taint analysis indicates one flow with unsanitized paths, though it's not classified as critical or high severity, which warrants attention. The plugin's clean vulnerability history is a positive sign, suggesting diligent development and maintenance. However, the absence of any recorded vulnerabilities could also mean it hasn't been extensively tested or targeted. The core weakness lies in the fundamental security principle of access control for AJAX operations, which if exploited, could lead to unauthorized actions or data manipulation. The plugin has strengths in its internal code hygiene but a critical flaw in its external interface security.
Key Concerns
- AJAX handlers without auth checks
- Flow with unsanitized paths (taint analysis)
SbS Settings Security Vulnerabilities
SbS Settings Release Timeline
SbS Settings Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
SbS Settings Attack Surface
AJAX Handlers 10
WordPress Hooks 114
Maintenance & Trust
SbS Settings Maintenance & Trust
Maintenance Signals
Community Trust
SbS Settings Alternatives
RationalCleanup
rationalcleanup
Clean up legacy WordPress bloat, improve security, and optimize performance with toggleable, opinionated defaults.
Wonderful Secure Cleanup
wonderful-secure-cleanup
A simple way to clean and secure WordPress by disabling unnecessary features like comments, XML-RPC, and RSS feeds.
ZenPress
zenpress
Speed up and harden your site with a single click: cleans up unused features, protects security gaps, and configures cache integrations automatically.
Mi13 Clean Up
mi13-clean-up
Описание
Session Shredder for WooCommerce
session-shredder-for-woocommerce
Smart rule-based pruning for WooCommerce 10.3+. Enhances experimental session storage with behavior signals to remove zombie sessions and cut DB size.
SbS Settings Developer Profile
1 plugin · 10 total installs
How We Detect SbS Settings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sbs-settings/assets/css/admin.css/wp-content/plugins/sbs-settings/assets/js/admin.js/wp-content/plugins/sbs-settings/assets/js/admin.jssbs-settings/assets/css/admin.css?ver=sbs-settings/assets/js/admin.js?ver=HTML / DOM Fingerprints
<!-- Silence is golden. -->data-nonce="sbsset_nonce"sbssetData