Small WP Security – SP SWS Security & Risk Analysis

wordpress.org/plugins/small-wp-security

Small WP Security is a WordPress plugin which provides the basic security of your site.

50 active installs v1.2 PHP + WP 4.5.3+ Updated Aug 21, 2018
hide-wp-versionremove-emojiremove-rsd-linkremove-rsssecurity-headers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Small WP Security – SP SWS Safe to Use in 2026?

Generally Safe

Score 85/100

Small WP Security – SP SWS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The small-wp-security plugin v1.2 exhibits a generally positive security posture based on the provided static analysis. The complete absence of attack surface points like AJAX handlers, REST API routes, and shortcodes, especially without authentication checks, significantly reduces its exploitability. Furthermore, the plugin demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests, and all SQL queries are protected with prepared statements. The presence of nonce checks and the lack of recorded vulnerability history are also strong indicators of a well-maintained and secure plugin.

However, a significant concern arises from the output escaping. With 33 total outputs and only 18% properly escaped, there is a high probability of cross-site scripting (XSS) vulnerabilities. While no specific taint flows with unsanitized paths were detected, this high rate of unescaped output represents a substantial risk. The complete lack of capability checks, while not directly an attack surface, means that even if functionalities were present, they wouldn't be restricted by user roles, which could be a secondary concern if the plugin evolves to include sensitive operations.

In conclusion, small-wp-security v1.2 scores well on preventing direct attacks due to its limited attack surface and secure data handling for SQL. The primary weakness lies in the insufficient output escaping, which warrants immediate attention to mitigate XSS risks. The absence of past vulnerabilities is a strength, suggesting diligent development, but the current output escaping issue needs to be addressed to maintain this secure standing.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Small WP Security – SP SWS Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Small WP Security – SP SWS Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
6 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

18% escaped33 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
sp_wp_security_admin_page_screen (sp-wp-security-admin.php:17)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Small WP Security – SP SWS Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionplugins_loadedsp-wp-functions.php:5
actionadmin_menusp-wp-security-admin.php:5
actioninitsp-wp-security-core.php:4
filterstyle_loader_srcsp-wp-security-core.php:60
filterscript_loader_srcsp-wp-security-core.php:61
actiondo_feedsp-wp-security-core.php:79
actiondo_feed_rdfsp-wp-security-core.php:80
actiondo_feed_rsssp-wp-security-core.php:81
actiondo_feed_rss2sp-wp-security-core.php:82
actiondo_feed_atomsp-wp-security-core.php:83
actionwpsp-wp-security-core.php:92
actionwpsp-wp-security-core.php:94
filtertiny_mce_pluginssp-wp-security-core.php:131
actioninitsp-wp-security-core.php:134
filterget_comment_author_linksp-wp-security-core.php:146
actionadmin_enqueue_scriptssp-wp-security-style.php:4
Maintenance & Trust

Small WP Security – SP SWS Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 21, 2018
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

Small WP Security – SP SWS Developer Profile

Alex Kuimov

9 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Small WP Security – SP SWS

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/small-wp-security/assets/css/admin.css/wp-content/plugins/small-wp-security/assets/css/font-awesome.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Small WP Security – SP SWS