Spam to blacklist Security & Risk Analysis

wordpress.org/plugins/spam-to-blacklist

Adds IP from comment that marked as spam to standard WordPress blacklist.

0 active installs v1.0 PHP + WP 4.9+ Updated Unknown
banblacklistcommentsipspam
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spam to blacklist Safe to Use in 2026?

Generally Safe

Score 100/100

Spam to blacklist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "spam-to-blacklist" v1.0 plugin exhibits an excellent security posture based on the provided static analysis. The complete absence of identified dangerous functions, raw SQL queries, file operations, external HTTP requests, and a lack of taint analysis findings suggest a well-written and secure codebase. Furthermore, the plugin demonstrates strong adherence to secure coding practices by having all SQL queries use prepared statements and all outputs properly escaped. The attack surface is effectively zero, with no AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for potential attackers. The vulnerability history is also pristine, with zero recorded CVEs, indicating a lack of previously discovered security flaws. This combination of robust code quality and a clean history paints a picture of a highly secure plugin. However, the complete absence of nonce checks and capability checks, while not a direct vulnerability given the zero attack surface, could become a concern if the plugin's functionality were ever to be expanded to include user-interactive features or administrative actions without proper authorization mechanisms in place. For its current state, the plugin is exceptionally secure.

Vulnerabilities
None known

Spam to blacklist Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Spam to blacklist Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Spam to blacklist Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionspam_commentspam-to-blacklist.php:37
actionunspam_commentspam-to-blacklist.php:38
Maintenance & Trust

Spam to blacklist Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Spam to blacklist Developer Profile

proninyaroslav

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spam to blacklist

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Spam to blacklist