Surbma | OptiMonk Security & Risk Analysis

wordpress.org/plugins/surbma-optimonk

OptiMonk for WordPress

20 active installs v2.1 PHP 7.0+ WP 5.1+ Updated Apr 8, 2023
exit-intentnewsletteroptimonkpop-uppopup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Surbma | OptiMonk Safe to Use in 2026?

Generally Safe

Score 85/100

Surbma | OptiMonk has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The surbma-optimonk v2.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code analysis shows no dangerous functions, no raw SQL queries (all use prepared statements), and no file operations or external HTTP requests, all of which are excellent security practices. The plugin also lacks bundled libraries, reducing the risk of relying on outdated or vulnerable third-party code.

However, a notable concern is the relatively low percentage of properly escaped output (57%). This indicates that there are instances where user-supplied data might be rendered without sufficient sanitization, potentially leading to cross-site scripting (XSS) vulnerabilities if such data is ever processed. The absence of nonce and capability checks on the limited entry points, while currently not exploitable due to the lack of entry points, represents a potential risk if the plugin were to evolve and introduce new functionalities that are not properly secured. The plugin's vulnerability history is clear, with no recorded CVEs, which is a positive indicator of its past security performance. In conclusion, while the plugin's current design minimizes the attack surface and employs secure coding practices for database interactions and file handling, the unescaped output presents a clear, albeit potentially isolated, risk that warrants attention.

Key Concerns

  • Output escaping is only 57% proper
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Surbma | OptiMonk Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Surbma | OptiMonk Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

57% escaped7 total outputs
Attack Surface

Surbma | OptiMonk Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initpages\settings-page.php:40
actionplugins_loadedsurbma-optimonk.php:31
actionwp_headsurbma-optimonk.php:57
Maintenance & Trust

Surbma | OptiMonk Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 8, 2023
PHP min version7.0
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Surbma | OptiMonk Developer Profile

Surbma

27 plugins · 30K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect Surbma | OptiMonk

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Surbma | OptiMonk