WP Maltor Security & Risk Analysis

wordpress.org/plugins/wp-maltor

This plugin blocks traffic from malicious IP and Tor Network

30 active installs v0.1.5 PHP + WP 3.3+ Updated Apr 15, 2016
block-trafficmalicioustor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Maltor Safe to Use in 2026?

Generally Safe

Score 85/100

WP Maltor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "wp-maltor" plugin version 0.1.5 exhibits a generally strong security posture based on the static analysis provided. The plugin has no recorded vulnerabilities, including no known CVEs, and no common vulnerability types. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, all identified SQL queries utilize prepared statements, and there are no external HTTP requests, indicating good practices in these critical areas. The taint analysis found no critical or high severity flows, suggesting that data sanitization and handling are likely robust. However, the plugin does have two file operations that are not detailed, and crucially, none of its total outputs are properly escaped. The lack of nonce checks and capability checks, while not directly exploitable given the limited attack surface, represent missed security best practices that could become a concern if the plugin's functionality were to expand. Overall, the plugin is currently low-risk due to its minimal attack surface and lack of historical vulnerabilities, but the unescaped output is a notable weakness that should be addressed.

Key Concerns

  • No output escaping
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

WP Maltor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Maltor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

WP Maltor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitwpmaltor.php:221
actionadmin_initwpmaltor.php:226
actionadmin_menuwpmaltor.php:228
Maintenance & Trust

WP Maltor Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 15, 2016
PHP min version
Downloads3K

Community Trust

Rating86/100
Number of ratings3
Active installs30
Developer Profile

WP Maltor Developer Profile

David Merinas

3 plugins · 210 total installs

68
trust score
Avg Security Score
63/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Maltor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
{{IMAGEN}}
FAQ

Frequently Asked Questions about WP Maltor