
Block Referral Spam Security & Risk Analysis
wordpress.org/plugins/wp-block-referral-spamThis plugins blocks maximum Referral Spams. Now no more notice from Google and no more weird report in Google Analytics.
Is Block Referral Spam Safe to Use in 2026?
Generally Safe
Score 85/100Block Referral Spam has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-block-referral-spam" plugin version 1.2.1 demonstrates a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unsanitized output, file operations, external HTTP requests, or taint flows is highly commendable and indicates diligent coding practices. The plugin also effectively utilizes capability checks, which is a crucial aspect of WordPress security for controlling access to functionality. The complete lack of known vulnerabilities in its history further reinforces its current security reliability.
However, the analysis also reveals a complete lack of entry points such as AJAX handlers, REST API routes, shortcodes, and cron events. While this drastically reduces the attack surface to zero, it also raises questions about the plugin's actual functionality and purpose. If the plugin is intended to provide active protection or perform any actions, the absence of any interaction points is unusual. The fact that there are no nonce checks is also noteworthy, though given the zero attack surface, this is not currently an immediate risk. The plugin's strengths lie in its clean code and lack of historical vulnerabilities, but its limited interactivity might be a point of investigation depending on its intended use.
Block Referral Spam Security Vulnerabilities
Block Referral Spam Code Analysis
Block Referral Spam Attack Surface
WordPress Hooks 3
Maintenance & Trust
Block Referral Spam Maintenance & Trust
Maintenance Signals
Community Trust
Block Referral Spam Alternatives
Analytics Spam Blocker
analytics-spam-blocker
Prevent referrer spam from affecting your website analytics. Easily create a blocklist and receive new domains weekly to stay on top of the issue.
WP referrer spam blacklist (fight 2040+ Referrer Spammers in (Google/Matomo) Analytics)
wp-referrer-spam-blacklist
WordPress plugin to fight with 2040+ referrer spammers (like semalt, buttons-for-website and many more).
Custom Referral Spam Blocker
custom-referral-spam-blocker
Custom Referral Spam Blocker gives you the control to ensure that dishonest referral sources are blocked from Google Analytics.
Referer Spam Blocker
referer-spam-blocker
Block/blacklist known (and custom) spam referring domains at the WordPress level with an HTTP 403 Forbidden page.
Block Referral Spam Developer Profile
46 plugins · 4.0M total installs
How We Detect Block Referral Spam
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-block-referral-spam/blocker.php