
Vulnerability Detector & Plugin Manager Security & Risk Analysis
wordpress.org/plugins/upkepr-maintenanceVulnerability Detector is a free plugin designed to secure your WordPress website by identifying known vulnerabilities in the WordPress.
Is Vulnerability Detector & Plugin Manager Safe to Use in 2026?
Generally Safe
Score 100/100Vulnerability Detector & Plugin Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The upkepr-maintenance plugin v1.0.12 presents a significant security risk due to a large, unprotected attack surface. All 11 identified entry points (4 AJAX handlers and 7 REST API routes) lack any form of authentication or permission checks. This means any unauthenticated user could potentially interact with these endpoints, leading to unauthorized actions or information disclosure.
While the plugin demonstrates good practices with SQL queries being 100% prepared and a lack of dangerous functions, the unescaped output is a concern, with only 36% properly escaped. This, combined with a single unsanitized path identified in the taint analysis, opens up potential for cross-site scripting (XSS) or other injection vulnerabilities if user-supplied data is not handled with extreme care within these unprotected endpoints. The absence of any known vulnerabilities in its history is positive but does not mitigate the immediate risks posed by the current code structure.
In conclusion, the plugin has some strengths, notably in its database query security. However, the complete lack of security measures on its entry points is a critical flaw that severely compromises its security posture and requires immediate attention.
Key Concerns
- AJAX handlers without auth checks
- REST API routes without permission callbacks
- Unescaped output is a concern (only 36% proper)
- Flows with unsanitized paths
Vulnerability Detector & Plugin Manager Security Vulnerabilities
Vulnerability Detector & Plugin Manager Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Vulnerability Detector & Plugin Manager Attack Surface
AJAX Handlers 4
REST API Routes 7
WordPress Hooks 3
Maintenance & Trust
Vulnerability Detector & Plugin Manager Maintenance & Trust
Maintenance Signals
Community Trust
Vulnerability Detector & Plugin Manager Alternatives
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall
malcare-security
Get Bulletproof Security for your WordPress site. WordPress security plugin packed with comprehensive Firewall, malware scanner, cleaner & more.
Plugin Security Scanner
plugin-security-scanner
This plugin alerts you if any of your plugins have security vulnerabilities. It does this by utilising the WPScan Vulnerability Database once a day.
WPLifeCycle – Free PHP Version Info & Website Manager
free-php-version-info
This plugin shows your current PHP version, its lifecycle security support days, and can send version data to the WPLifeCycle for proactive planning.
WP Scanner – Performance and Security
wp-scanner
Scan your WordPress site and receive recommendations on how to improve load time, performance and security.
Vulnerability Detector & Plugin Manager Developer Profile
1 plugin · 10 total installs
How We Detect Vulnerability Detector & Plugin Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/upkepr-maintenance/css/style.css/wp-content/plugins/upkepr-maintenance/css/enchancestyle.css/wp-content/plugins/upkepr-maintenance/js/dataTables.min.js/wp-content/plugins/upkepr-maintenance/js/bootstrap.bundle.min.js/wp-content/plugins/upkepr-maintenance/css/dataTables.dataTables.min.css/wp-content/plugins/upkepr-maintenance/js/upkepr_script.jsupkepr-maintenance/style.css?ver=upkepr-maintenance/enchancestyle.css?ver=upkepr-maintenance/dataTables.min.js?ver=upkepr-maintenance/bootstrap.bundle.min.js?ver=upkepr-maintenance/dataTables.dataTables.min.css?ver=upkepr-maintenance/upkepr_script.js?ver=HTML / DOM Fingerprints
upkepr-admin-page<!-- Main Wrapper Start --><!-- Vulnerability Detector & Plugin Manager - Main Wrapper End -->data-upkepr-license-keyupkpr_ajax_object/wp-json/upkepr-maintenance/v1/get-data/wp-json/upkepr-maintenance/v1/update-settings