XMLRPC Lockdown by AO Digital Security & Risk Analysis

wordpress.org/plugins/xmlrpc-lockdown

XMLRPC Lockdown by AO Digital is an advanced security plugin for WordPress. It blocks access to xmlrpc.php for all requests except those explicitly al …

80 active installs v2.0 PHP 8.0+ WP + Updated Dec 10, 2024
jetpackmobile-appsecuritywordpressxmlrpc
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is XMLRPC Lockdown by AO Digital Safe to Use in 2026?

Generally Safe

Score 92/100

XMLRPC Lockdown by AO Digital has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The xmlrpc-lockdown plugin version 2.0 exhibits a strong security posture based on the provided static analysis. All identified entry points, including AJAX handlers, are protected by nonce checks. The code adheres to best practices by exclusively using prepared statements for SQL queries and properly escaping all output, indicating a robust defense against common injection vulnerabilities. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and critical or high-severity taint flows suggests careful coding and a minimal attack surface.

The plugin's vulnerability history is also commendable, with zero known CVEs. This, combined with the clean static analysis, implies a well-maintained and secure codebase that has not historically been a target for exploitation or has effectively mitigated potential risks. The lack of any recorded vulnerabilities, regardless of severity, is a significant positive indicator.

In conclusion, xmlrpc-lockdown v2.0 appears to be a secure plugin. Its strengths lie in its adherence to fundamental WordPress security practices, such as proper nonce and output sanitization, and its clean vulnerability history. While the absence of capability checks on AJAX handlers could theoretically be a minor concern in highly complex scenarios, the presence of nonce checks significantly mitigates this risk. Overall, the plugin presents a low-risk profile.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

XMLRPC Lockdown by AO Digital Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

XMLRPC Lockdown by AO Digital Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
xmlrpcld_save_allowed_plugins (includes\ajax.php:6)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

XMLRPC Lockdown by AO Digital Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_save_allowed_pluginsincludes\ajax.php:2
authwp_ajax_add_custom_allowanceincludes\ajax.php:3
authwp_ajax_remove_custom_allowanceincludes\ajax.php:4
WordPress Hooks 5
actionadmin_enqueue_scriptsincludes\admin.php:201
filterxmlrpc_enabledincludes\block-logic.php:61
actionadmin_menuxmlrpclockdown.php:25
actionadmin_enqueue_scriptsxmlrpclockdown.php:26
actioninitxmlrpclockdown.php:29
Maintenance & Trust

XMLRPC Lockdown by AO Digital Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 10, 2024
PHP min version8.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

XMLRPC Lockdown by AO Digital Developer Profile

aodigitalau

2 plugins · 80 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect XMLRPC Lockdown by AO Digital

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xmlrpc-lockdown/css/admin.css/wp-content/plugins/xmlrpc-lockdown/js/admin.js
Script Paths
/wp-content/plugins/xmlrpc-lockdown/js/admin.js
Version Parameters
xmlrpc-lockdown/css/admin.css?ver=xmlrpc-lockdown/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
checkbox-grid
JS Globals
xmlrpcld_allowed_plugins_nonce
FAQ

Frequently Asked Questions about XMLRPC Lockdown by AO Digital