
WP Show Site by IP Security & Risk Analysis
wordpress.org/plugins/wp-show-site-by-ipHide your Wordpress website to unknown IPs and replace it with a HTML page. Useful for developers to work online in private (e.g. maintenance).
Is WP Show Site by IP Safe to Use in 2026?
Generally Safe
Score 85/100WP Show Site by IP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-show-site-by-ip v2.4.0 plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by utilizing prepared statements for all SQL queries and performing nonce checks on its single AJAX handler. However, a significant concern arises from the lack of authentication checks on this AJAX handler. This creates a direct entry point for unauthenticated users to interact with the plugin's functionality, potentially leading to unintended consequences or information disclosure depending on the AJAX handler's implementation.
The static analysis reveals a small attack surface, with only one AJAX handler identified. While the absence of critical taint flows and dangerous functions is positive, the 38% rate of properly escaped output is a weakness. This suggests that some user-provided data, if not handled carefully within the plugin's code, could be vulnerable to cross-site scripting (XSS) attacks when displayed to users.
The plugin has no recorded vulnerability history, which is a positive indicator of its past security. This suggests that the developers have either been diligent in addressing issues or that the plugin's functionality has not historically attracted significant security attention. Nevertheless, the current findings of an unprotected AJAX endpoint and incomplete output escaping warrant attention. While the vulnerability history is clean, the static analysis highlights areas where improvements can enhance the plugin's overall security.
Key Concerns
- AJAX handler without auth checks
- Low output escaping rate (38%)
WP Show Site by IP Security Vulnerabilities
WP Show Site by IP Code Analysis
Output Escaping
WP Show Site by IP Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
WP Show Site by IP Maintenance & Trust
Maintenance Signals
Community Trust
WP Show Site by IP Alternatives
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Maintenance
maintenance
Great looking maintenance, coming soon & under construction pages. Put your site under maintenance in minutes.
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode
coming-soon
Easy Drag & Drop Page Builder. A complete solution to create a WordPress Website, Custom Themes, Landing Pages, Coming Soon & Maintenance Mode Pages.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content
password-protected
Protect your WordPress site, pages, posts, WooCommerce products, and categories with single or multiple passwords.
WP Show Site by IP Developer Profile
3 plugins · 80 total installs
How We Detect WP Show Site by IP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-show-site-by-ip/css/main.css/wp-content/plugins/wp-show-site-by-ip/lib/prism/prism.css/wp-content/plugins/wp-show-site-by-ip/lib/prism/prism.js/wp-content/plugins/wp-show-site-by-ip/js/main.js/wp-content/plugins/wp-show-site-by-ip/lib/ace-1.2.5/src-min-noconflict/ace.js/wp-content/plugins/wp-show-site-by-ip/lib/tlite-0.0.5/tlite.min.js/wp-content/plugins/wp-show-site-by-ip/js/help-pointer.js/wp-content/plugins/wp-show-site-by-ip/js/main.js/wp-content/plugins/wp-show-site-by-ip/lib/ace-1.2.5/src-min-noconflict/ace.js/wp-content/plugins/wp-show-site-by-ip/lib/tlite-0.0.5/tlite.min.js/wp-content/plugins/wp-show-site-by-ip/js/help-pointer.js/wp-content/plugins/wp-show-site-by-ip/lib/prism/prism.jswp-show-site-by-ip/js/main.js?ver=wp-show-site-by-ip/css/main.css?ver=wp-show-site-by-ip/lib/prism/prism.css?ver=wp-show-site-by-ip/lib/prism/prism.js?ver=wp-show-site-by-ip/js/help-pointer.js?ver=HTML / DOM Fingerprints
wp-pointerwp-pointer-bottomwp-pointer-arrowwp-pointer-topwp-pointer-undefineddata-targetwssbiHelpPointerwssbiL10n