
What's going on Security & Risk Analysis
wordpress.org/plugins/whats-going-onA simple Web Application Firewall for WordPress.
Is What's going on Safe to Use in 2026?
Generally Safe
Score 85/100What's going on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "whats-going-on" plugin version 1.3 exhibits a mixed security posture. While it has a clean vulnerability history with no recorded CVEs, indicating a potentially mature and well-maintained codebase, the static analysis reveals several areas for concern. A significant portion of its attack surface, specifically one out of seven AJAX handlers, lacks proper authentication checks, presenting a direct pathway for unauthorized access and potential manipulation.
Furthermore, the taint analysis highlights 3 high-severity flows with unsanitized paths, suggesting a risk of injection vulnerabilities if user-controlled data is not handled meticulously. The relatively low percentage of properly escaped output (31%) is another red flag, increasing the likelihood of cross-site scripting (XSS) vulnerabilities. Despite the majority of SQL queries utilizing prepared statements, the presence of file operations and an unprotected AJAX endpoint are potential vectors for exploitation.
In conclusion, while the plugin's lack of known vulnerabilities is a positive indicator, the identified weaknesses in its attack surface, taint analysis, and output escaping warrant careful attention. These issues, particularly the unprotected AJAX handler and high-severity taint flows, represent concrete risks that could be exploited by malicious actors. It is crucial to address these specific findings to improve the overall security of the plugin.
Key Concerns
- AJAX handler without authentication check
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped output
What's going on Security Vulnerabilities
What's going on Release Timeline
What's going on Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
What's going on Attack Surface
AJAX Handlers 7
WordPress Hooks 11
Scheduled Events 5
Maintenance & Trust
What's going on Maintenance & Trust
Maintenance Signals
Community Trust
What's going on Alternatives
Login Security, FireWall, Malware removal by CleanTalk
security-malware-firewall
Brute force, Login security & Two Factor Auth (2FA). Limit login. Malware & Vulnerabilities scan. FireWall. Enterprise ready security plugin.
Security Ninja – WordPress Security & Firewall
security-ninja
WordPress security plugin with free basic firewall/WAF, vulnerability and core scanning, and 50+ core integrity checks.
Advanced IP Blocker
advanced-ip-blocker
A complete WordPress security firewall: blocks IPs, bots & countries. Includes an intelligent WAF, Threat Scoring, Geo-Challenge, 2FA, and Anti-Sp …
BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security
bitfire
Real-time firewall that stops bots, malware, and hackers with real AI, file protection, and traffic analytics without slowing down your site
Anti-Hacker – Security Plugin
anti-hacker
Anti-Hacker protects your Wordpress against hackers attacks, hiding sensitive information that would be used to exploit your site, detecting and fixin …
What's going on Developer Profile
2 plugins · 0 total installs
How We Detect What's going on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whats-going-on/lib/datatables.min.css/wp-content/plugins/whats-going-on/lib/svgMap.min.css/wp-content/plugins/whats-going-on/lib/wgo.min.css/wp-content/plugins/whats-going-on/lib/pdfmake.min.js/wp-content/plugins/whats-going-on/lib/vfs_fonts.js/wp-content/plugins/whats-going-on/lib/datatables.min.js/wp-content/plugins/whats-going-on/lib/pdfmake.min.js/wp-content/plugins/whats-going-on/lib/vfs_fonts.js/wp-content/plugins/whats-going-on/lib/datatables.min.jswhats-going-on/lib/datatables.min.css?ver=whats-going-on/lib/svgMap.min.css?ver=whats-going-on/lib/wgo.min.css?ver=whats-going-on/lib/pdfmake.min.js?ver=whats-going-on/lib/vfs_fonts.js?ver=whats-going-on/lib/datatables.min.js?ver=HTML / DOM Fingerprints
wgo-containerdata-wgo-pagewgo_autoreload_datatables