ST Admin Protection Security & Risk Analysis

wordpress.org/plugins/st-admin-protection

This plugin blocks everyone but the admin from accessing the Wordpresss Admin

10 active installs v1.0.0 PHP + WP 3.0+ Updated Oct 9, 2011
adminformfront-endpost
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ST Admin Protection Safe to Use in 2026?

Generally Safe

Score 85/100

ST Admin Protection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "st-admin-protection" plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code adheres to secure coding practices, demonstrating 100% usage of prepared statements for SQL queries and proper output escaping, with no dangerous functions or file operations detected. The single capability check indicates a conscious effort to protect at least some functionality.

No critical, high, or even medium vulnerabilities have been recorded in its history, and there are no known CVEs associated with this plugin. The taint analysis also reveals no identified flows with unsanitized paths, further reinforcing the impression of well-secured code. The lack of bundled libraries is also a positive sign as it avoids potential vulnerabilities from outdated third-party components. The plugin appears to be designed with security as a priority, focusing on minimizing potential exposure points and implementing robust internal checks where applicable.

Vulnerabilities
None known

ST Admin Protection Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ST Admin Protection Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

ST Admin Protection Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitst-admin-protection.php:39
Maintenance & Trust

ST Admin Protection Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedOct 9, 2011
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ST Admin Protection Developer Profile

shayne

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ST Admin Protection

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<!-- ST Admin Protection -->
FAQ

Frequently Asked Questions about ST Admin Protection