Security Ninja – WordPress Security & Firewall

security-ninja · by cleverplugins · wordpress.org ↗ · SVN ↗
Active installs
7k+
Current version
5.303
Added
2016-08-30
Last updated
2026-09-08 (12d ago)
First seen by beacon
5mo ago
Total downloads
899,921

Statistics

2024-06-17 → 2026-09-10 · 806 days
Downloads today
273
7-day total 3,814
Week over week
▼ -39%
vs prior 7 days
30-day trend
declining
▲ +774% MoM
Abandonment
○○○○○
healthy
Downloads/day Linear trend
7k5k3k2k02024-062024-102025-032025-072025-122026-042026-09
3k2k1k67002026-062026-062026-072026-072026-082026-08
3k2k1k67002026-082026-082026-082026-082026-092026-09

Active versions

other5.3035.235
other · 47.8%5.303 · 20.9%5.235 · 17.8%5.244 · 7.8%5.289 · 5.8%

Ratings

5★
91
4★
1
3★
0
2★
1
1★
7

Support: 0/0 resolved

Alerts (0)

No open alerts.

Show 1 resolved alert
Critical code_pattern Resolved · false_positive_defensive_string_check 2026-04-30 15:25:29 (4mo ago)
Slugsecurity-ninja
Patternserialized_admin_role
Kindbuiltin
Version5.281
Hit count2
First hit
File
modules/events-logger/events-logger.php
Line
206
Snippet
'%s:13:"administrator"%',
Explanationplugin source contains `s:13:"administrator"` — the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand.
View raw JSON
{
    "slug": "security-ninja",
    "pattern": "serialized_admin_role",
    "kind": "builtin",
    "version": "5.281",
    "hit_count": 2,
    "first_hit": {
        "file": "modules/events-logger/events-logger.php",
        "line": 206,
        "snippet": "'%s:13:\"administrator\"%',"
    },
    "explanation": "plugin source contains `s:13:\"administrator\"` \u2014 the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand."
}

SVN committers (4)

Accounts with actual commit access to security-ninja on plugins.svn.wordpress.org, reconstructed from svn log. This is the list that matters for ownership changes — not the readme contributors.

Committer Member since Commits First commit Latest commit
Lars Koudal 2005-09-06 99 2022-04-28 · r2716169 2026-09-08 · r3686974
cleverplugins 2017-05-19 85 2019-08-23 · r2144450 2022-04-06 · r2705839
WebFactory 2012-02-27 51 2016-08-30 · r1486351 2020-10-01 · r2391852
plugin-master 2007-03-09 1 2016-08-29 · r1485997 2016-08-29 · r1485997

Readme contributors (3)

Names the plugin's readme declares as contributors. A soft signal — anyone can be listed. The SVN access column is the ground-truth cross-reference: does this contributor actually commit code?

Contributor Member since SVN access Status
Lars Koudal 2005-09-06 99 commits Active
cleverplugins 2017-05-19 85 commits Active
Freemius 2014-12-16 Active

Versions (12 most recent)

Version Released Download
5.303 zip
5.302 zip
5.301 zip
5.296 zip
5.299 zip
5.300 zip
5.289 zip
5.286 2026-06-02 · 3mo ago zip
5.283 2026-05-19 · 4mo ago zip
5.281 2026-04-23 · 5mo ago
5.277 zip
5.279 2026-04-16 · 5mo ago zip