
WP Security By Made I.T. Security & Risk Analysis
wordpress.org/plugins/wp-security-by-made-itSecure your WordPress Website.
Is WP Security By Made I.T. Safe to Use in 2026?
Generally Safe
Score 100/100WP Security By Made I.T. has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-security-by-made-it' plugin v1.8.3 presents a mixed security posture. While it boasts a clean vulnerability history with no known CVEs, indicating a good track record of security maintenance or limited exposure, the static analysis reveals significant concerns. A substantial attack surface is exposed, with all 8 identified AJAX handlers lacking authentication checks. This means any authenticated user could potentially trigger these handlers, leading to unintended actions.
The taint analysis further highlights critical security risks. The presence of one critical severity flow with an unsanitized path suggests that user-supplied input could be used to influence sensitive operations, potentially leading to code execution or data manipulation. Additionally, the static analysis flags the use of dangerous functions like 'exec' and 'shell_exec', which, combined with unsanitized input, pose a severe risk of remote code execution.
Despite the clean CVE history, the identified vulnerabilities in the static analysis are serious enough to warrant caution. The lack of capability checks on AJAX handlers is a major oversight. While the use of prepared statements for SQL queries is positive, the presence of critical taint flows and dangerous function usage overrides this strength. This plugin should be treated with a high degree of suspicion until these critical issues are addressed.
Key Concerns
- AJAX handlers without auth checks
- Critical severity taint flow
- Use of dangerous functions (exec, shell_exec)
- Flows with unsanitized paths
- Capability checks: 0
WP Security By Made I.T. Security Vulnerabilities
WP Security By Made I.T. Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Security By Made I.T. Attack Surface
AJAX Handlers 8
WordPress Hooks 22
Scheduled Events 21
Maintenance & Trust
WP Security By Made I.T. Maintenance & Trust
Maintenance Signals
Community Trust
WP Security By Made I.T. Alternatives
SX User Name Security
user-name-security
SX User Name Security prevents WordPress from showing your real Login everywhere. It ovverides the body_class function, User Nicename, Nickname and Di …
Virus Finder
virus-finder
Find viruses in your WordPress easily. Virus scan, malware finder.
SecuPress with Simple SSL – Simple and Performant Security
secupress
Protect your WordPress with SecuPress, analyze and ensure the safety of your website daily.
SP Move Login
sf-move-login
Move your WordPress login page to protect it from bots. This plugin contains the Move Login module from SecuPress. Other security modules are availabl …
WebDefender Security – Protection & AntiSpam
cwis-antivirus-malware-detected
PRO Security – Antivirus Scanner, 2-Layer Protection Hide Security, Brute Force Security & Antispam, Security Website and Security Hardening.
WP Security By Made I.T. Developer Profile
2 plugins · 110 total installs
How We Detect WP Security By Made I.T.
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-security-by-made-it/admin/css/bootstrap.css/wp-content/plugins/wp-security-by-made-it/admin/css/admin.css/wp-content/plugins/wp-security-by-made-it/admin/js/bootstrap.min.js/wp-content/plugins/wp-security-by-made-it/admin/js/admin.jswp-security-by-made-it/admin/css/bootstrap.css?ver=wp-security-by-made-it/admin/css/admin.css?ver=wp-security-by-made-it/admin/js/bootstrap.min.js?ver=wp-security-by-made-it/admin/js/admin.js?ver=HTML / DOM Fingerprints
update-pluginsupdate-countMADEIT_SECURITY_URL