Simple blueprint installer Security & Risk Analysis

wordpress.org/plugins/simple-blueprint-installer

Install this as your first plugin and make easy and fast the first setup of your WordPress.

20 active installs v1.0.2 PHP 5.2.4+ WP 4.6+ Updated Nov 16, 2019
blueprintdelete-default-contentinstallationinstallersetup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple blueprint installer Safe to Use in 2026?

Generally Safe

Score 85/100

Simple blueprint installer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The 'simple-blueprint-installer' v1.0.2 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent practices regarding SQL queries, utilizing prepared statements exclusively, and ensuring all output is properly escaped, which significantly reduces the risk of SQL injection and cross-site scripting (XSS) vulnerabilities. The absence of known CVEs and a clean vulnerability history further suggest a generally well-maintained codebase.

However, a significant concern arises from the plugin's attack surface. All four identified AJAX handlers lack authentication checks, creating a direct pathway for unauthenticated attackers to interact with sensitive functionalities. While taint analysis did not reveal critical or high-severity issues, the presence of two flows with unsanitized paths, even if deemed lower severity in this analysis, warrants caution. This, combined with the unprotected AJAX endpoints, could potentially be chained by an attacker to exploit specific plugin logic.

In conclusion, while the plugin excels in core secure coding practices like prepared statements and output escaping, the lack of authentication on its AJAX endpoints represents a substantial security weakness. The vulnerability history is encouraging, but the identified attack surface issues require immediate attention to mitigate potential risks.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
Vulnerabilities
None known

Simple blueprint installer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple blueprint installer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
85 escaped
Nonce Checks
7
Capability Checks
7
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped85 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
control_form_settings_tab (admin\class-simple-blueprint-installer-admin.php:323)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Simple blueprint installer Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_sbi_plugins_operatecore\class-simple-blueprint-installer.php:181
authwp_ajax_sbi_plugins_installercore\class-simple-blueprint-installer.php:182
authwp_ajax_sbi_plugin_installercore\class-simple-blueprint-installer.php:183
authwp_ajax_sbi_plugin_activationcore\class-simple-blueprint-installer.php:184
WordPress Hooks 10
actionplugins_loadedcore\class-simple-blueprint-installer.php:148
actionadmin_enqueue_scriptscore\class-simple-blueprint-installer.php:167
actionadmin_enqueue_scriptscore\class-simple-blueprint-installer.php:168
actionadmin_initcore\class-simple-blueprint-installer.php:173
filterinstall_plugins_tabscore\class-simple-blueprint-installer.php:174
actioninstall_plugins_sbi_blueprintcore\class-simple-blueprint-installer.php:175
actioninstall_plugins_sbi_setupcore\class-simple-blueprint-installer.php:176
actionadmin_post_sbi_setup_formcore\class-simple-blueprint-installer.php:177
actionwp_enqueue_scriptscore\class-simple-blueprint-installer.php:203
actionwp_enqueue_scriptscore\class-simple-blueprint-installer.php:204
Maintenance & Trust

Simple blueprint installer Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedNov 16, 2019
PHP min version5.2.4
Downloads3K

Community Trust

Rating100/100
Number of ratings7
Active installs20
Developer Profile

Simple blueprint installer Developer Profile

pablocianes

4 plugins · 260 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple blueprint installer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-blueprint-installer/admin/css/simple-blueprint-installer-admin.min.css/wp-content/plugins/simple-blueprint-installer/admin/js/simple-blueprint-installer-admin.min.js
Script Paths
/wp-content/plugins/simple-blueprint-installer/admin/js/simple-blueprint-installer-admin.min.js
Version Parameters
simple-blueprint-installer/admin/css/simple-blueprint-installer-admin.min.css?ver=simple-blueprint-installer/admin/js/simple-blueprint-installer-admin.min.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Currently plugin version. --><!-- The code that runs only in dev mode --><!-- Simple blueprint installer by Cianes' WP Suite is free software: you can redistribute it and/or modify --><!-- Simple blueprint installer by Cianes' WP Suite is distributed in the hope that it will be useful, -->+25 more
Data Attributes
sbi_installer_nonce
JS Globals
sbi_installer_localize
FAQ

Frequently Asked Questions about Simple blueprint installer