
WebTotem Security Security & Risk Analysis
wordpress.org/plugins/wt-securityWebTotem is a SaaS which provides powerful tools for securing and monitoring your website in one place in easy and flexible way.
Is WebTotem Security Safe to Use in 2026?
Generally Safe
Score 100/100WebTotem Security has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wt-security" plugin v2.4.35 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and has no recorded vulnerabilities in its history, suggesting a potentially stable codebase. The absence of dangerous functions, file operations, and external HTTP requests further contribute to a lower risk profile in these specific areas.
However, significant security concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This is a critical oversight, as it allows any unauthenticated user to trigger these functionalities, potentially leading to unauthorized actions or information disclosure. Furthermore, the complete lack of output escaping on 13 identified outputs is a major weakness. This opens the door to Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the context of other users' browsers.
The plugin's vulnerability history shows no recorded CVEs, which is positive. However, this should not be taken as a definitive indicator of perfect security, especially given the identified weaknesses in the current version. The lack of taint analysis results could indicate that the analysis was not performed or that no complex taint flows were detected, but it doesn't negate the direct risks identified in the static analysis. In conclusion, while the plugin avoids certain common pitfalls like raw SQL and has a clean vulnerability record, the unprotected AJAX endpoints and widespread unescaped output pose substantial risks that need immediate attention.
Key Concerns
- AJAX handlers without authentication
- Unescaped output across multiple locations
- AJAX handlers without capability checks
- No nonce checks on AJAX handlers
WebTotem Security Security Vulnerabilities
WebTotem Security Code Analysis
Output Escaping
WebTotem Security Attack Surface
AJAX Handlers 2
WordPress Hooks 58
Scheduled Events 2
Maintenance & Trust
WebTotem Security Maintenance & Trust
Maintenance Signals
Community Trust
WebTotem Security Alternatives
NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall
ninjafirewall
A true Web Application Firewall to protect and secure WordPress.
Zero Spam for WordPress
zero-spam
No spam, no scams, just seamless experiences with Zero Spam for WordPress - the shield your site deserves.
Virusdie – One-click website security
virusdie
Malware scanning & removal, website hardening, patching vulnerabilities, real-time protection against online attacks, blacklist monitoring in a click!
QueryWall: Plug'n Play Firewall
querywall
Autopilot protection for your WordPress against malicious URL requests.
SAR One Click Security
sar-one-click-security
Adds some extra security to your WordPress with only one click.
WebTotem Security Developer Profile
1 plugin · 900 total installs
How We Detect WebTotem Security
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wt-security/assets/css/backend.css/wp-content/plugins/wt-security/assets/css/frontend.css/wp-content/plugins/wt-security/assets/js/backend.js/wp-content/plugins/wt-security/assets/js/frontend.js/wp-content/plugins/wt-security/assets/js/backend.js/wp-content/plugins/wt-security/assets/js/frontend.jswt-security/assets/css/backend.css?ver=wt-security/assets/css/frontend.css?ver=wt-security/assets/js/backend.js?ver=wt-security/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wtotem-headerwtotem-menuwtotem-logowtotem-admin-bar-menuwtotem-admin-bar-sub-menuwtotem-scan-result<!-- Protected By WebTotem! -->data-wt-ajax-urlwindow.wtotem_ajax_urlwindow.wtotem_nonces