Security Control by Reflecters Security & Risk Analysis

wordpress.org/plugins/security-controll-by-reflecters

WordPress security plugin detects new devices, blocks them with a password, triggers siren alerts, and lets master admin control user access.

0 active installs v1.1 PHP 7.4+ WP 5.5+ Updated Sep 13, 2025
admin-protectiondevice-authenticationlogin-securitysecuritysiren-alert
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Security Control by Reflecters Safe to Use in 2026?

Generally Safe

Score 100/100

Security Control by Reflecters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "security-controll-by-reflecters" plugin version 1.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code demonstrates excellent adherence to security best practices, with all identified AJAX handlers protected by authentication checks, no REST API routes present, and no shortcodes or cron events that could serve as entry points. The absence of dangerous functions, reliance on prepared statements for SQL queries, and proper output escaping for all outputs further bolster its security. Nonce and capability checks are extensively implemented, indicating a robust defense against common web attacks.

Further bolstering this positive assessment is the complete lack of any recorded vulnerabilities or CVEs, either historical or current. This suggests a well-maintained and secure codebase, or at least one that has not yet been identified as having flaws. The taint analysis also shows no critical or high severity issues, confirming that there are no obvious pathways for malicious data injection or manipulation through the analyzed flows. The plugin's strengths lie in its thorough authentication and authorization mechanisms, and its absence of known exploitable flaws.

While the plugin appears secure based on the data, it's important to note that the attack surface, while protected, consists of six AJAX handlers. Although all have authentication checks, a larger number of entry points can still increase the overall maintenance burden and the theoretical possibility of undiscovered vulnerabilities. However, given the strong evidence of secure coding practices and the lack of historical issues, the overall risk is assessed as very low. The plugin is well-implemented with security as a clear priority.

Vulnerabilities
None known

Security Control by Reflecters Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Security Control by Reflecters Release Timeline

v1.1Current
Code Analysis
Analyzed Mar 17, 2026

Security Control by Reflecters Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
125 escaped
Nonce Checks
9
Capability Checks
15
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped125 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<security-controll-by-reflecters> (security-controll-by-reflecters.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Security Control by Reflecters Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_scbr_stop_sirensecurity-controll-by-reflecters.php:44
authwp_ajax_scbr_block_usersecurity-controll-by-reflecters.php:45
authwp_ajax_scbr_unblock_usersecurity-controll-by-reflecters.php:46
authwp_ajax_scbr_trust_devicesecurity-controll-by-reflecters.php:47
authwp_ajax_scbr_remove_devicesecurity-controll-by-reflecters.php:48
authwp_ajax_scbr_mute_sirensecurity-controll-by-reflecters.php:49
WordPress Hooks 19
actionplugins_loadedsecurity-controll-by-reflecters.php:30
actioninitsecurity-controll-by-reflecters.php:34
actionadmin_initsecurity-controll-by-reflecters.php:35
actionadmin_enqueue_scriptssecurity-controll-by-reflecters.php:38
actionadmin_footersecurity-controll-by-reflecters.php:39
actionadmin_noticessecurity-controll-by-reflecters.php:40
actionin_admin_headersecurity-controll-by-reflecters.php:41
actionadmin_menusecurity-controll-by-reflecters.php:52
actionadmin_noticessecurity-controll-by-reflecters.php:53
actionadmin_post_scbr_set_mastersecurity-controll-by-reflecters.php:54
actionadmin_post_scbr_save_settingssecurity-controll-by-reflecters.php:55
actionadmin_post_scbr_trust_resetsecurity-controll-by-reflecters.php:56
actionadmin_noticessecurity-controll-by-reflecters.php:58
actionadmin_noticessecurity-controll-by-reflecters.php:106
actionadmin_noticessecurity-controll-by-reflecters.php:402
actionadmin_noticessecurity-controll-by-reflecters.php:439
actionadmin_noticessecurity-controll-by-reflecters.php:514
actionadmin_noticessecurity-controll-by-reflecters.php:522
actionadmin_noticessecurity-controll-by-reflecters.php:569
Maintenance & Trust

Security Control by Reflecters Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 13, 2025
PHP min version7.4
Downloads265

Community Trust

Rating100/100
Number of ratings21
Active installs0
Developer Profile

Security Control by Reflecters Developer Profile

Reflecters

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Security Control by Reflecters

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/security-controll-by-reflecters/assets/css/admin.css/wp-content/plugins/security-controll-by-reflecters/assets/css/frontend.css/wp-content/plugins/security-controll-by-reflecters/assets/js/admin.js/wp-content/plugins/security-controll-by-reflecters/assets/js/frontend.js
Version Parameters
security-controll-by-reflecters/assets/css/admin.css?ver=security-controll-by-reflecters/assets/css/frontend.css?ver=security-controll-by-reflecters/assets/js/admin.js?ver=security-controll-by-reflecters/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
scbr-overlayscbr-siren-headerscbr-siren-bodyscbr-siren-footerscbr-admin-notice-warning
HTML Comments
<!-- SCBR: Security Control by Reflecters -->
Data Attributes
data-siren-actiondata-siren-noncedata-nonce-actiondata-nonce-valuedata-actiondata-user-id
JS Globals
window.scbr_admin_paramswindow.scbr_frontend_params
FAQ

Frequently Asked Questions about Security Control by Reflecters