
Security Assassin Security & Risk Analysis
wordpress.org/plugins/security-assassinIt protects against third-party access the file system on your site Hide your site from users who did not login Hide your site from some users regist …
Is Security Assassin Safe to Use in 2026?
Generally Safe
Score 85/100Security Assassin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "security-assassin" v1.1.4 plugin exhibits a mixed security posture. On the surface, it presents a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The lack of external HTTP requests and no recorded vulnerability history are also positive indicators, suggesting a generally stable and unexploited codebase. However, the static analysis reveals significant underlying weaknesses.
A primary concern is the complete absence of nonce checks and capability checks. This means that any functionality exposed by the plugin, even if not directly apparent from the listed entry points, could potentially be executed by unauthenticated or unauthorized users. The single SQL query identified is not using prepared statements, posing a risk of SQL injection. Furthermore, the lack of output escaping on all identified outputs is a critical vulnerability, making cross-site scripting (XSS) attacks highly probable.
While the plugin has no known CVEs, this is likely due to the fundamental security flaws present in its code rather than inherent resilience. The complete lack of taint analysis flows analyzed is also concerning, as it suggests the static analysis tool may not have been able to effectively probe the plugin's code for deeper vulnerabilities. In conclusion, despite a seemingly small attack surface and no public vulnerability history, "security-assassin" v1.1.4 has critical security flaws related to authorization, input validation (SQL injection), and output sanitization (XSS) that require immediate attention.
Key Concerns
- Raw SQL without prepared statements
- 0% output escaping
- 0 Nonce checks
- 0 Capability checks
Security Assassin Security Vulnerabilities
Security Assassin Release Timeline
Security Assassin Code Analysis
SQL Query Safety
Output Escaping
Security Assassin Attack Surface
WordPress Hooks 8
Maintenance & Trust
Security Assassin Maintenance & Trust
Maintenance Signals
Community Trust
Security Assassin Alternatives
CryptX
cryptx
No more SPAM by spiders scanning your site for email addresses!
WP Mailto Links – Protect Email Addresses
wp-mailto-links
Protect & encode email addresses safely from spambots & spamming. Easy to use - encodes emails out-of-the-box.
Email No Bot – Prevent bots from detecting emails
email-no-bot
Humans will see the email address on your page, but robots will not.
Advanced Email Filter for Elementor Forms
advanced-email-filter-for-elementor-forms
Enhance Elementor Pro Forms with advanced email filtering capabilities including global blocklists/whitelist and per-form controls.
wL Email Encrypter
wl-email-encrypter
This plugin encrypted e-mail addresses to protect and hide them from bots and harvesters.
Security Assassin Developer Profile
1 plugin · 10 total installs
How We Detect Security Assassin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!--Security Assassin START --><!--Security Assassin END -->