SpinupWP Security & Risk Analysis

wordpress.org/plugins/spinupwp

SpinupWP is a modern server control panel that's here to help you implement best practices for every server you spin up. Designed for WordPress.

30K active installs v1.9.0 PHP 7.1+ WP 4.7+ Updated Dec 8, 2025
cachecachingperformance
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SpinupWP Safe to Use in 2026?

Generally Safe

Score 100/100

SpinupWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The SpinupWP plugin v1.9.0 exhibits a generally strong security posture with no recorded vulnerabilities and a limited attack surface. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating nonce and capability checks on its entry points. The absence of external HTTP requests and bundled libraries also minimizes potential risks. However, the presence of the `unserialize` function, a known source of vulnerabilities if not handled with extreme care, represents a specific area of concern. Additionally, the low percentage of properly escaped output suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, particularly if data processed by `unserialize` is subsequently outputted without adequate sanitization. While taint analysis shows no immediate risks, the combination of `unserialize` and poor output escaping warrants careful review and mitigation.

Key Concerns

  • Dangerous function unserialize found
  • Low output escaping percentage (29%)
Vulnerabilities
None known

SpinupWP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SpinupWP Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
5
2 escaped
Nonce Checks
2
Capability Checks
6
File Operations
11
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$value = @unserialize( $original );drop-ins\object-cache.php:2749

Output Escaping

29% escaped7 total outputs
Attack Surface

SpinupWP Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_spinupwp_dismiss_noticesrc\AdminNotices.php:26
WordPress Hooks 24
filterpre_determine_localedrop-ins\object-cache.php:2911
actionadmin_bar_menusrc\AdminBar.php:30
actionadmin_enqueue_scriptssrc\AdminBar.php:31
actionadmin_enqueue_scriptssrc\AdminNotices.php:25
actionnetwork_admin_noticessrc\AdminNotices.php:29
actionadmin_noticessrc\AdminNotices.php:31
actioninitsrc\Cache.php:43
actionspinupwp_purge_object_cachesrc\Cache.php:44
actionspinupwp_purge_page_cachesrc\Cache.php:45
actionspinupwp_purge_urlsrc\Cache.php:46
actionadmin_initsrc\Cache.php:47
actiontransition_post_statussrc\Cache.php:48
actiondelete_postsrc\Cache.php:49
actionswitch_themesrc\Cache.php:50
actioncomment_postsrc\Cache.php:51
actionwp_set_comment_statussrc\Cache.php:52
actionupgrader_process_completesrc\Cache.php:53
actionshutdownsrc\Cache.php:234
actionelementor/core/files/clear_cachesrc\Compatibility\ElementorPlugin.php:26
actionplugins_loadedsrc\MagicLogin.php:29
actionadmin_initsrc\Plugin.php:50
filterspinupwp_should_use_object_cache_dropinsrc\Plugin.php:56
filtersite_status_testssrc\SiteHealth.php:11
filtersite_status_page_cache_supported_cache_headerssrc\SiteHealth.php:12
Maintenance & Trust

SpinupWP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 8, 2025
PHP min version7.1
Downloads465K

Community Trust

Rating100/100
Number of ratings13
Active installs30K
Developer Profile

SpinupWP Developer Profile

Brad Touesnard

1 plugin · 30K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SpinupWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SpinupWP