Virusdie – One-click website security Security & Risk Analysis

wordpress.org/plugins/virusdie

Malware scanning & removal, website hardening, patching vulnerabilities, real-time protection against online attacks, blacklist monitoring in a click!

2K active installs v1.1.8 PHP 5.6+ WP 5.0+ Updated Jan 30, 2026
antivirusfirewallmalware-scannersecuritysecurity-plugin
95
A · Safe
CVEs total4
Unpatched0
Last CVEFeb 18, 2026
Download
Safety Verdict

Is Virusdie – One-click website security Safe to Use in 2026?

Generally Safe

Score 95/100

Virusdie – One-click website security has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Feb 18, 2026Updated 3mo ago
Risk Assessment

The Virusdie plugin v1.1.8 exhibits a mixed security posture. On one hand, the static analysis shows a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. Furthermore, all detected SQL queries use prepared statements, which is a strong defense against SQL injection. However, concerns arise from the output escaping, where only 43% of outputs are properly escaped, indicating a potential risk for Cross-Site Scripting (XSS) vulnerabilities. The presence of one flow with an unsanitized path, although not classified as critical or high, warrants attention as it could be a vector for path traversal or similar attacks.

The plugin's vulnerability history is a significant concern. With four known medium-severity CVEs, all of which are currently unpatched according to the provided data, this plugin carries a substantial risk. The common types of vulnerabilities found (Exposure of Sensitive Information, Missing Authorization, CSRF) are serious and suggest recurring issues with access control and data handling. The fact that the last vulnerability was reported in 2026 indicates that these are recent and unaddressed security flaws.

In conclusion, while the plugin has a minimal attack surface and good practices in database query handling, the unpatched historical vulnerabilities and the moderate percentage of unescaped output present significant risks. The presence of unsanitized paths also adds to the potential attack vectors. Users should exercise extreme caution and prioritize patching or finding an alternative if these vulnerabilities remain unaddressed.

Key Concerns

  • 4 unpatched medium severity CVEs
  • 43% of outputs not properly escaped
  • 1 flow with unsanitized path
Vulnerabilities
4 published

Virusdie – One-click website security Security Vulnerabilities

CVEs by Year

3 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
4

4 total CVEs

CVE-2025-14864medium · 4.3Missing Authorization

Virusdie <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) API Key Disclosure

Feb 18, 2026 Patched in 1.1.8 (1d)
CVE-2025-68576medium · 4.3Exposure of Sensitive Information to an Unauthorized Actor

Virusdie <= 1.1.6 - Authenticated (Subscriber+) Information Exposure

Dec 21, 2025 Patched in 1.1.7 (17d)
CVE-2025-68577medium · 4.3Missing Authorization

Virusdie <= 1.1.6 - Missing Authorization

Dec 21, 2025 Patched in 1.1.7 (17d)
CVE-2025-53265medium · 4.3Cross-Site Request Forgery (CSRF)

Virusdie <= 1.1.3 - Cross-Site Request Forgery

Jun 27, 2025 Patched in 1.1.4 (20d)
Code Analysis
Analyzed Mar 16, 2026

Virusdie – One-click website security Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
121
93 escaped
Nonce Checks
1
Capability Checks
0
File Operations
9
External Requests
1
Bundled Libraries
0

Output Escaping

43% escaped214 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
init (inc\tools\class-virusdie-behavior.php:24)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Virusdie – One-click website security Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitinc\class-virusdie.php:57
actionwp_logoutinc\class-virusdie.php:60
actionwp_logininc\class-virusdie.php:61
actionplugins_loadedinc\class-virusdie.php:63
actionadmin_menuinc\class-virusdie.php:64
Maintenance & Trust

Virusdie – One-click website security Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 30, 2026
PHP min version5.6
Downloads35K

Community Trust

Rating80/100
Number of ratings9
Active installs2K
Developer Profile

Virusdie – One-click website security Developer Profile

Virusdie

1 plugin · 2K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect Virusdie – One-click website security

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/virusdie/assets/css/virusdie.css/wp-content/plugins/virusdie/assets/css/jquery-jvectormap-2.0.5.css/wp-content/plugins/virusdie/assets/js/vdws-socketio.js/wp-content/plugins/virusdie/assets/js/progressbar.js/wp-content/plugins/virusdie/assets/js/vdws-login.js/wp-content/plugins/virusdie/assets/js/vdws-account.js/wp-content/plugins/virusdie/assets/js/vdws-scan.js/wp-content/plugins/virusdie/assets/js/vdws-resend.js
Script Paths
https://new.virusdie.com/socket.io/socket.io.js
Version Parameters
virusdie/assets/css/virusdie.css?ver=virusdie/assets/css/jquery-jvectormap-2.0.5.css?ver=virusdie/assets/js/vdws-socketio.js?ver=virusdie/assets/js/progressbar.js?ver=virusdie/assets/js/vdws-login.js?ver=virusdie/assets/js/vdws-account.js?ver=virusdie/assets/js/vdws-scan.js?ver=virusdie/assets/js/vdws-resend.js?ver=

HTML / DOM Fingerprints

CSS Classes
vdws-loginvdws-scanvdws-progressbar
HTML Comments
<!-- Plugin Name: Virusdie | One-click website security --><!-- Description: One-Click Website security with Virusdie Wordpress Plugin --><!-- Primary class file for the Virusdie Plugin. --><!-- Make sure the file is not directly accessible. -->+17 more
Data Attributes
data-vdws-apikeydata-vdws-id
JS Globals
VDWS_VIRUSDIE_PLUGIN_VERSIONVDWS_VIRUSDIE_PLUGIN_URLVDWS_VIRUSDIE_SITE_PANELvdws_site_urlvdws_api_keyvdws_current_user_id+2 more
FAQ

Frequently Asked Questions about Virusdie – One-click website security