Some Plus Bulk Manager Security & Risk Analysis

wordpress.org/plugins/some-plus-bulk-manager

Clean up your WordPress site with bulk operations and undo functionality. Delete inactive users, orphaned media, spam comments, revisions, and more.

0 active installs v1.1.3 PHP 7.4+ WP 5.0+ Updated Mar 25, 2026
bulkcleanupoptimizationtrashundo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Some Plus Bulk Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Some Plus Bulk Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "some-plus-bulk-manager" v1.1.3 plugin demonstrates a generally strong security posture based on the provided static analysis. It adheres to several best practices, including the exclusive use of prepared statements for its SQL queries and proper escaping of all output. The plugin also implements a good number of nonce and capability checks, indicating a deliberate effort to protect its entry points. There are no known vulnerabilities or CVEs associated with this plugin, which further contributes to a positive security assessment.

However, a few areas warrant attention. The presence of one flow with unsanitized paths, even if not classified as critical or high severity by taint analysis, represents a potential for indirect manipulation or unexpected behavior if not carefully handled. Additionally, the plugin makes one external HTTP request, which, while not inherently a vulnerability, introduces an external dependency that could be a vector for supply chain attacks or unintended data exposure if the external service is compromised. The limited attack surface is a positive, but the single AJAX handler, though reported as protected, is still an entry point that requires ongoing vigilance.

Overall, "some-plus-bulk-manager" v1.1.3 appears to be a well-developed plugin with a focus on secure coding practices. The absence of historical vulnerabilities is a significant strength. The identified taint flow and external HTTP request are minor concerns that should be monitored, but they do not indicate immediate critical risks given the current analysis.

Key Concerns

  • Flow with unsanitized paths detected
  • External HTTP request made
Vulnerabilities
None known

Some Plus Bulk Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Some Plus Bulk Manager Release Timeline

v1.1.3Current
Code Analysis
Analyzed Apr 16, 2026

Some Plus Bulk Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
110 prepared
Unescaped Output
0
366 escaped
Nonce Checks
7
Capability Checks
16
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared110 total queries

Output Escaping

100% escaped366 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

5 flows1 with unsanitized paths
ajax_scan (includes/modules/class-module-broken-links.php:117)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Some Plus Bulk Manager Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_spbm_scan_broken_linksincludes/modules/class-module-broken-links.php:277
WordPress Hooks 6
filtercron_schedulesincludes/class-cron-manager.php:34
filterspbm_skip_trashincludes/class-cron-manager.php:271
actionadmin_menuincludes/class-module-registry.php:62
actionadmin_enqueue_scriptsincludes/class-module-registry.php:63
actioninitincludes/class-some-plus-bulk-manager.php:60
actionplugins_loadedsome-plus-bulk-manager.php:63
Maintenance & Trust

Some Plus Bulk Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 25, 2026
PHP min version7.4
Downloads79

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Some Plus Bulk Manager Developer Profile

someplus

3 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Some Plus Bulk Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/some-plus-bulk-manager/assets/css/admin.css/wp-content/plugins/some-plus-bulk-manager/assets/js/admin.js
Script Paths
/wp-content/plugins/some-plus-bulk-manager/assets/js/admin.js
Version Parameters
/wp-content/plugins/some-plus-bulk-manager/assets/css/admin.css?ver=/wp-content/plugins/some-plus-bulk-manager/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
spbm-badgespbm-badge--userspbm-badge--postspbm-badge--revisionspbm-badge--commentspbm-badge--buddypress_signuptitle-countspbm-card__count
Data Attributes
data-stat
JS Globals
spbm
REST Endpoints
/wp-json/some-plus-bulk-manager/
FAQ

Frequently Asked Questions about Some Plus Bulk Manager