
SULly Security & Risk Analysis
wordpress.org/plugins/sullySystem Update Logger - Record system updates including plugins, themes and core updates.
Is SULly Safe to Use in 2026?
Generally Safe
Score 89/100SULly has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'sully' v4.4 exhibits a mixed security posture. While the static analysis reports a very small attack surface with no apparent unprotected entry points (AJAX, REST API, shortcodes, cron), several concerning code signals exist. The presence of the `unserialize` function, a known vector for deserialization vulnerabilities if input is not strictly controlled, is a significant red flag. Furthermore, a substantial portion of SQL queries (12%) are not using prepared statements, increasing the risk of SQL injection, and nearly 60% of output is not properly escaped, posing a Cross-Site Scripting (XSS) risk. The vulnerability history indicates a pattern of past medium severity issues, primarily XSS and CSRF, with the most recent recorded on June 22, 2024. The fact that there are currently no unpatched CVEs is positive, but the recurring types of vulnerabilities suggest potential ongoing weaknesses in input validation and output sanitization, despite some positive indicators like nonce and capability checks.
Key Concerns
- Dangerous function `unserialize` found
- SQL queries not using prepared statements
- Output not properly escaped
- Past medium severity vulnerabilities (4 total)
SULly Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
SULly <= 4.3.0 - Authenticated (Admin+) Stored Cross-Site Scripting
SULly <= 4.3 - Reflected Cross-Site Scripting
SULly <= 4.3.0 - Cross-Site Request Forgery to Plugin Reset
SULly <= 4.3.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
SULly Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
SULly Attack Surface
WordPress Hooks 8
Maintenance & Trust
SULly Maintenance & Trust
Maintenance Signals
Community Trust
SULly Alternatives
No alternatives data available yet.
SULly Developer Profile
34 plugins · 8K total installs
How We Detect SULly
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sully/includes/css/sully-dashboard.css/wp-content/plugins/sully/includes/js/sully-dashboard.jsHTML / DOM Fingerprints
sully-dashboard-widgetid="sully-dashboard-widget"