
Login Security, FireWall, Malware removal by CleanTalk Security & Risk Analysis
wordpress.org/plugins/security-malware-firewallBrute force, Login security & Two Factor Auth (2FA). Limit login. Malware & Vulnerabilities scan. FireWall. Enterprise ready security plugin.
Is Login Security, FireWall, Malware removal by CleanTalk Safe to Use in 2026?
Generally Safe
Score 86/100Login Security, FireWall, Malware removal by CleanTalk has a strong security track record. Known vulnerabilities have been patched promptly.
The security-malware-firewall plugin version 2.174 presents a mixed security posture. While it demonstrates some positive security practices, such as a high percentage of SQL queries using prepared statements and a reasonable number of capability checks, significant concerns are evident. The large attack surface, with 66 AJAX handlers and a concerning 48 of them lacking authentication checks, is a major weakness. This exposes a significant portion of the plugin's functionality to potential unauthorized access and manipulation. Furthermore, only 29% of output escaping is properly handled, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, although limited in scope with only 8 flows, reveals 4 with unsanitized paths, which is concerning for potential injection vulnerabilities.
Key Concerns
- High number of AJAX handlers without auth checks
- Low percentage of properly escaped output
- Taint analysis shows unsanitized paths
- Numerous past vulnerabilities with critical/high severity
- History of 'Missing Authorization' vulnerabilities
- History of 'Cross-site Scripting' vulnerabilities
- History of 'SQL Injection' vulnerabilities
Login Security, FireWall, Malware removal by CleanTalk Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Login Security, FireWall, Malware removal by CleanTalk <= 2.168 - Unauthenticated Stored Cross-Site Scripting via Page URL
Security & Malware scan by CleanTalk <= 2.149 - Unauthenticated Arbitrary File Upload
Security & Malware scan by CleanTalk <= 2.145 - Authorization Bypass via Reverse DNS Spoofing to Unauthenticated SQL Injection
Security & Malware scan by CleanTalk <= 2.120 - IP Spoofing to Protection Mechanism Bypass
Security & Malware scan by CleanTalk <= 2.50 - Missing Authorization
Login Security, FireWall, Malware removal by CleanTalk Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Login Security, FireWall, Malware removal by CleanTalk Attack Surface
AJAX Handlers 66
Shortcodes 1
WordPress Hooks 67
Maintenance & Trust
Login Security, FireWall, Malware removal by CleanTalk Maintenance & Trust
Maintenance Signals
Community Trust
Login Security, FireWall, Malware removal by CleanTalk Alternatives
All-In-One Security (AIOS) – Security and Firewall
all-in-one-wp-security-and-firewall
Protect your website investment with All-In-One Security (AIOS) – a comprehensive and easy to use security plugin designed especially for WordPress.
Security Optimizer – The All-In-One Protection Plugin
sg-security
Secure your WordPress site from brute-force attacks, threats, malware, and bots. Free to use and easy to set up.
Defender Security – Malware Scanner, Login Security & Firewall
defender-security
WordPress security plugin with malware scanner, IP blocking, audit logs, antivirus scans, firewall, 2FA, brute force login security, and more.
BulletProof Security
bulletproof-security
WordPress Security Protection: Malware scanner, Firewall, Login Security, DB Backup, Anti-Spam...
Security Ninja – WordPress Security Plugin & Firewall
security-ninja
WordPress security plugin with free basic firewall/WAF, vulnerability scanning, and 50+ core integrity checks.
Login Security, FireWall, Malware removal by CleanTalk Developer Profile
5 plugins · 230K total installs
How We Detect Login Security, FireWall, Malware removal by CleanTalk
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/security-malware-firewall/src/css/spbc_admin.css/wp-content/plugins/security-malware-firewall/src/css/spbc_frontend.css/wp-content/plugins/security-malware-firewall/src/js/spbc_admin.js/wp-content/plugins/security-malware-firewall/src/js/spbc_frontend.js/wp-content/plugins/security-malware-firewall/src/js/spbc_admin.js/wp-content/plugins/security-malware-firewall/src/js/spbc_frontend.jssecurity-malware-firewall/src/css/spbc_admin.css?ver=security-malware-firewall/src/css/spbc_frontend.css?ver=security-malware-firewall/src/js/spbc_admin.js?ver=security-malware-firewall/src/js/spbc_frontend.js?ver=HTML / DOM Fingerprints
spbc-admin-noticespbc-statsspbc-scan-resultsspbc-logs-table<!-- SPBC: Settings --><!-- SPBC: Logs --><!-- SPBC: Scan Results --><!-- SPBC: Firewall -->data-spbc-scan-iddata-spbc-log-iddata-spbc-firewall-rulewindow.spbc_admin_datawindow.spbc_frontend_datavar spbc_vars/wp-json/spbc/v1/scan/wp-json/spbc/v1/logs/wp-json/spbc/v1/settings[spbc_firewall_message][spbc_scan_status]