
Throws SPAM Away Security & Risk Analysis
wordpress.org/plugins/throws-spam-awayスパムコメントを無視して何もなかったように捨てる強力スパム対策プラグイン
Is Throws SPAM Away Safe to Use in 2026?
Generally Safe
Score 99/100Throws SPAM Away has a strong security track record. Known vulnerabilities have been patched promptly.
The "throws-spam-away" v3.8.2 plugin exhibits a mixed security posture. While it demonstrates good practices in areas like output escaping and minimizing file operations, significant concerns arise from its unprotected attack surface and taint analysis results. The presence of two AJAX handlers without authentication checks presents a direct pathway for attackers to interact with the plugin's functionality without proper authorization. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential vulnerabilities where user-controlled input could be used in a malicious way. The plugin's history includes a past high-severity vulnerability, specifically CSRF, which, while currently patched, suggests a pattern of past security weaknesses that require continued vigilance. The overall security is weakened by the direct exposure of functionality and potential for sensitive data handling issues, despite its efforts in other security areas.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Past high severity vulnerability
- SQL queries not fully prepared
- Untrusted input in some flows
Throws SPAM Away Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Throws SPAM Away <= 3.3 - Cross-Site Request Forgery to Comment Modification
Throws SPAM Away Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Throws SPAM Away Attack Surface
AJAX Handlers 2
WordPress Hooks 7
Maintenance & Trust
Throws SPAM Away Maintenance & Trust
Maintenance Signals
Community Trust
Throws SPAM Away Alternatives
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
Captcha Code
captcha-code-authentication
GDPR compatible captcha anti-spam protection for login form, comments form, registration form & lost password form. Eliminate spam with captcha.
Throws SPAM Away Developer Profile
2 plugins · 20K total installs
How We Detect Throws SPAM Away
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/throws-spam-away/js/tsa_main.js/wp-content/plugins/throws-spam-away/css/tsa_main.css/wp-content/plugins/throws-spam-away/js/tsa_main.jsthrows-spam-away/js/tsa_main.js?ver=throws-spam-away/css/tsa_main.css?ver=HTML / DOM Fingerprints
tsa-spam-away<!-- Throws SPAM Away startThrows SPAM Away end -->tsa_main