
Surbma | WP Control Security & Risk Analysis
wordpress.org/plugins/surbma-wp-controlVery useful fixes and add-ons for WordPress Multisite installations.
Is Surbma | WP Control Safe to Use in 2026?
Generally Safe
Score 92/100Surbma | WP Control has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "surbma-wp-control" v21.0 plugin exhibits an excellent security posture. The plugin demonstrates strong adherence to secure coding practices, with no identified dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. Furthermore, the absence of file operations and external HTTP requests minimizes common attack vectors. The lack of any recorded vulnerabilities, including CVEs, further reinforces this positive assessment. This suggests a proactive and well-maintained security approach by the developers.
While the current analysis shows no direct vulnerabilities, it's important to note that the plugin reports zero entry points that require authentication. This could be a strength if the plugin genuinely has no user-facing interactions that need protection, or a potential area for concern if there are unaddressed functionalities. The zero nonce checks and capability checks also align with this observation, indicating that the plugin might not be designed for complex or user-specific interactions that would typically require such security measures. However, the complete absence of any identified issues in the static analysis is a significant positive indicator of secure development.
Key Concerns
- No unprotected AJAX handlers
- No unprotected REST API routes
- No dangerous functions used
- All SQL queries use prepared statements
- All output is properly escaped
- No file operations detected
- No external HTTP requests detected
- No nonce checks detected
- No capability checks detected
- No unsanitized taint flows
- No known CVEs
Surbma | WP Control Security Vulnerabilities
Surbma | WP Control Code Analysis
Surbma | WP Control Attack Surface
WordPress Hooks 5
Maintenance & Trust
Surbma | WP Control Maintenance & Trust
Maintenance Signals
Community Trust
Surbma | WP Control Alternatives
Unconfirmed
unconfirmed
Allows WordPress admins to manage unactivated users, by activating them manually, deleting their pending registrations, or resending the activation em …
Network Username Restrictions Override
network-username-restrictions-override
Override restrictions on WordPress network usernames.
Plugin Activation Status
plugin-activation-status
Scans a multisite or multi-network installation to identify all plugins that are active or not.
WP Over Network
wp-over-network
Add ability to get posts from over your network sites. Supports widget, shortcode, and customizable original function.
Multisite Enhancements
multisite-enhancements
Enhance Multisite for Network Admins with different topics
Surbma | WP Control Developer Profile
27 plugins · 30K total installs
How We Detect Surbma | WP Control
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- Global site tag (gtag.js) - Google Analytics -->gtagdataLayer