
Melapress File Monitor Security & Risk Analysis
wordpress.org/plugins/website-file-changes-monitorGet email alerts for file and permission changes on your WordPress sites. No false positives!
Is Melapress File Monitor Safe to Use in 2026?
Generally Safe
Score 95/100Melapress File Monitor has a strong security track record. Known vulnerabilities have been patched promptly.
This plugin exhibits a concerning security posture primarily due to a significant number of unprotected AJAX handlers, representing a large attack surface that could be exploited by unauthenticated users. While the plugin demonstrates good practices in its use of prepared statements for SQL queries and proper output escaping, the 14 unprotected AJAX endpoints are a critical weakness. The presence of the `unserialize` function also raises a red flag, as it can lead to deserialization vulnerabilities if not handled with extreme care, especially when dealing with user-controlled input. The plugin's vulnerability history, with four known CVEs including one high-severity SQL injection and three medium-severity vulnerabilities, highlights a pattern of past security oversights. Although no CVEs are currently unpatched, the recurring nature of these issues suggests potential ongoing security challenges and the need for more rigorous development and testing practices. Overall, while some good security practices are in place, the substantial unprotected attack surface and past vulnerability trends indicate a notable risk.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function unserialize
- Past high severity vulnerability (SQLi)
- Past medium severity vulnerabilities
Melapress File Monitor Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Melapress File Monitor < 2.2.0 - Missing Authorization
Melapress File Monitor <= 2.0.2 - Authenticated (Admin+) Authenticated SQL Injection
Melapress File Monitor <= 2.1.0 - Authenticated (Admin+) Authenticated SQL Injection
Website File Changes Monitor <= 1.8.2 - Authenticated (Admin+) SQL Injection
Melapress File Monitor Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Melapress File Monitor Attack Surface
AJAX Handlers 16
REST API Routes 1
WordPress Hooks 22
Maintenance & Trust
Melapress File Monitor Maintenance & Trust
Maintenance Signals
Community Trust
Melapress File Monitor Alternatives
File Change Monitor
file-change-monitor
Detects file changes in WordPress core, themes, and plugins. Sends email alerts to the site admin.
File Inspection
file-inspection
The plugin creates MD5 hash from every file in your blog.
Files Inspector
files-inspector
Compare files changes within wordpress.
Recent File Scanner
recent-file-scanner
Scan themes and plugins for newly created files added in the last N days. Great for detecting suspicious uploads.
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Melapress File Monitor Developer Profile
6 plugins · 417K total installs
How We Detect Melapress File Monitor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/website-file-changes-monitor/assets/js/script.js/wp-content/plugins/website-file-changes-monitor/assets/css/style.css/wp-content/plugins/website-file-changes-monitor/assets/js/script.jswebsite-file-changes-monitor/assets/js/script.js?ver=website-file-changes-monitor/assets/css/style.css?ver=HTML / DOM Fingerprints
mfm-settings-form<!-- MFM Admin Settings Form --><!-- MFM Dashboard Widget -->data-mfm-settingswindow.mfm_settings/wp-json/mfm/v1/settings/wp-json/mfm/v1/logs