
VigilanTor Security & Risk Analysis
wordpress.org/plugins/vigilantorAdd a layer of security to your WordPress site with the ability to block Tor users from commenting, registering, logging in and more.
Is VigilanTor Safe to Use in 2026?
Generally Safe
Score 85/100VigilanTor has a strong security track record. Known vulnerabilities have been patched promptly.
The 'vigilantor' v1.3.12 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and includes a reasonable number of nonce and capability checks. The absence of dangerous functions and file operations is also a positive sign.
However, there are significant concerns stemming from the static analysis. The presence of an unprotected AJAX handler presents a direct entry point for potential attacks. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating a risk of sensitive data being processed without proper validation or sanitization, even though no critical or high severity taint issues were flagged. The output escaping is also a weakness, with only 20% of outputs being properly escaped, which significantly increases the risk of cross-site scripting (XSS) vulnerabilities.
The vulnerability history shows one medium severity CVE related to XSS. While there are no currently unpatched vulnerabilities, the past XSS vulnerability, combined with the low percentage of properly escaped output, suggests a recurring weakness in input sanitization and output encoding. The plugin's strengths lie in its database interaction security, but its handling of user-supplied data for output and its exposed AJAX endpoint are clear areas of concern that require attention.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- Low percentage of output escaping
- Medium severity CVE in history
VigilanTor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
VigilanTor <= 1.3.10 - Authenticated (Administrator+) Stored Cross-Site Scripting
VigilanTor Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
VigilanTor Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 20
Scheduled Events 1
Maintenance & Trust
VigilanTor Maintenance & Trust
Maintenance Signals
Community Trust
VigilanTor Alternatives
Proxy & VPN Blocker
proxy-vpn-blocker
Block VPNs, proxies, Tor, and spam on WordPress. Strengthen security and stop fake users with smart IP blocking via proxycheck.io.
Identityplus
identity-plus
Identityplus is a novel security solution based on PKI (Public Key Infrastructure) called a network of trust. It features an all-in-one 2 (ocasionally …
Free Net of Moderators
moderateit
Maintaining a culture of online communication in the hands of the users themselves.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
VigilanTor Developer Profile
1 plugin · 400 total installs
How We Detect VigilanTor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vigilantor/css/securimage-style.css/wp-content/plugins/vigilantor/css/admin.css/wp-content/plugins/vigilantor/js/admin.js/wp-content/plugins/vigilantor/js/admin.jsvigilantor/css/securimage-style.css?ver=vigilantor/css/admin.css?ver=vigilantor/js/admin.js?ver=HTML / DOM Fingerprints
vitor-admin-wrap<!-- VigilanTor --><!-- VigilanTor Admin -->data-vitor-flagvar vitor_ajax_urlvar vitor_nonce[tor_users][non_tor_users]