Spam Destroyer Security & Risk Analysis

wordpress.org/plugins/spam-destroyer

Kills spam dead in it's tracks. Be gone evil demon spam!

6K active installs v2.1.6 PHP + WP 5.0+ Updated May 1, 2025
anti-spamantispambuddypresscommentsspam
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spam Destroyer Safe to Use in 2026?

Generally Safe

Score 100/100

Spam Destroyer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "spam-destroyer" v2.1.6 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, critical taint flows, raw SQL queries, and a relatively well-handled attack surface are significant strengths. The plugin appears to follow good practices by utilizing prepared statements for all SQL queries and implementing nonce and capability checks on some functions. However, there are minor areas for improvement. The presence of file operations and external HTTP requests, while not inherently risky without further context, warrants careful review to ensure they are handled securely and do not introduce vulnerabilities. Furthermore, the 18% of outputs that are not properly escaped could potentially lead to cross-site scripting (XSS) vulnerabilities if the data being outputted originates from user input or untrusted sources. The lack of reported vulnerabilities in its history is positive, suggesting a history of stable and secure development, but it doesn't guarantee future security.

Key Concerns

  • Outputs not properly escaped
  • File operations detected
  • External HTTP requests detected
Vulnerabilities
None known

Spam Destroyer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Spam Destroyer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
28 escaped
Nonce Checks
1
Capability Checks
2
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

82% escaped34 total outputs
Attack Surface

Spam Destroyer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 24
actionadmin_initinc\class-dotorg-plugin-review.php:47
actionadmin_initinc\class-dotorg-plugin-review.php:48
actionadmin_noticesinc\class-dotorg-plugin-review.php:122
actionmanage_comments_custom_columninc\class-spam-destroyer-add-meta.php:25
actionwp_insert_commentinc\class-spam-destroyer-add-meta.php:26
filtermanage_edit-comments_columnsinc\class-spam-destroyer-add-meta.php:29
filterplugin_row_metainc\class-spam-destroyer-settings.php:18
actionspam_destroyer_deathinc\class-spam-destroyer-stats.php:32
actioninitinc\class-spam-destroyer.php:36
filterpreprocess_commentinc\class-spam-destroyer.php:50
filterbbp_new_topic_pre_contentinc\class-spam-destroyer.php:51
filterbbp_new_reply_pre_contentinc\class-spam-destroyer.php:52
filterwpmu_validate_blog_signupinc\class-spam-destroyer.php:53
filterwpmu_validate_user_signupinc\class-spam-destroyer.php:54
filterantispam-checkinc\class-spam-destroyer.php:57
filterantispam-fieldsinc\class-spam-destroyer.php:58
actioncomment_forminc\class-spam-destroyer.php:61
actionsignup_hidden_fieldsinc\class-spam-destroyer.php:62
actionbp_after_registration_submit_buttonsinc\class-spam-destroyer.php:63
actionbbp_theme_before_topic_form_contentinc\class-spam-destroyer.php:64
actionbbp_theme_before_reply_form_contentinc\class-spam-destroyer.php:65
actionregister_forminc\class-spam-destroyer.php:66
actionadmin_noticesinc\class-spam-destroyer.php:67
actioninitinc\class-spam-destroyer.php:68
Maintenance & Trust

Spam Destroyer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMay 1, 2025
PHP min version
Downloads99K

Community Trust

Rating92/100
Number of ratings53
Active installs6K
Developer Profile

Spam Destroyer Developer Profile

Ryan Hellyer

14 plugins · 97K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spam Destroyer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/spam-destroyer/assets/kill.js
Script Paths
assets/kill.js
Version Parameters
spam-destroyer/assets/kill.js?ver=

HTML / DOM Fingerprints

JS Globals
spam_destroyer
FAQ

Frequently Asked Questions about Spam Destroyer