Snack Ads Security & Risk Analysis

wordpress.org/plugins/snack-ads

Handles automatic update of ad units for publishers who advertise with Snack Media.

20 active installs v2.1.1 PHP 7.0+ WP 5.3+ Updated Nov 28, 2025
advertising
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Snack Ads Safe to Use in 2026?

Generally Safe

Score 100/100

Snack Ads has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "snack-ads" v2.1.1 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no identified critical or high-severity taint flows, and all SQL queries utilize prepared statements, indicating good practices in data handling and preventing SQL injection. The absence of known CVEs and a clean vulnerability history is also a strong indicator of a secure codebase.

However, several concerning patterns emerge from the static analysis. The complete lack of nonce checks and capability checks across all entry points, including a cron event, presents a significant risk of Cross-Site Request Forgery (CSRF) and unauthorized action execution. Furthermore, the analysis shows that 100% of the single identified output is not properly escaped, which is a critical vulnerability leading to Cross-Site Scripting (XSS) attacks. The presence of file operations and external HTTP requests without associated security checks also introduces potential risks if these operations are not handled with utmost care.

In conclusion, while "snack-ads" v2.1.1 avoids common pitfalls like raw SQL and critical taint flows, the complete absence of input validation (nonces, capabilities) and the unescaped output are severe deficiencies that expose users to significant XSS and CSRF risks. The plugin's strengths lie in its SQL handling and lack of past major vulnerabilities, but these are overshadowed by the immediate and exploitable weaknesses in output sanitization and access control.

Key Concerns

  • Unescaped output detected
  • No nonce checks on entry points
  • No capability checks on entry points
  • Potential risk with file operations
  • Potential risk with external HTTP requests
Vulnerabilities
None known

Snack Ads Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Snack Ads Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Snack Ads Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitsnack-ads.php:35
actionadmin_noticessnack-ads.php:43
actionsnack_ads_plugin_deactivatesnack-ads.php:60
actionrest_api_initsnack-ads.php:87
actioninitsnack-ads.php:95

Scheduled Events 1

snack_ads_force_update
Maintenance & Trust

Snack Ads Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Snack Ads Developer Profile

BoUk

5 plugins · 440 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Snack Ads

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/snack-ads/resources/css/snack-ads-admin.css/wp-content/plugins/snack-ads/resources/js/snack-ads-admin.js

HTML / DOM Fingerprints

REST Endpoints
/wp-json/snack/ads/v1/update
FAQ

Frequently Asked Questions about Snack Ads