Plugin Security Certification (PSC-2025-64597): “Redis Object Cache” – Version 2.6.5: Use Cache with Enhanced Security

Plugin Security Certification (PSC-2025-64597): “Redis Object Cache” – Version 2.6.5: Use Cache with Enhanced Security

Redis Object Cache 2.6.5 is a persistent object cache backend powered by Redis®¹, designed to enhance WordPress performance and scalability. It supports multiple PHP clients such as Predis, PhpRedis (PECL), and Relay, while offering advanced features like replication, sentinels, clustering, and seamless WP-CLI integration.

Plugin Security Certification (PSC-2025-64596): “PDF Embedder” – Version 4.9.2: Use PDF with Enhanced Security

Plugin Security Certification (PSC-2025-64596): “PDF Embedder” – Version 4.9.2: Use PDF with Enhanced Security

PDF Embedder is a powerful WordPress plugin that allows you to upload and embed PDF files directly into posts and pages, offering seamless document presentation with responsive design. Unlike other plugins that rely on iframes, PDF Embedder uses a unique JavaScript-based rendering method that gives site administrators complete control over the look, sizing, and navigation of embedded PDFs.

The plugin ensures that all PDF files and associated scripts are served from your own server, guaranteeing both faster performance and greater reliability, without reliance on third-party services. This approach enhances not only the user experience but also the security of your content.

The free version includes essential embedding functionality, while PDF Embedder Premium extends features with download options, hyperlink support, continuous scrolling, full-screen mode, and advanced mobile-friendly options.

Plugin Security Certification (PSC-2025-64593): “Meta pixel for WordPress” – Version 4.1.5: Use Logs with Enhanced Security

Plugin Security Certification (PSC-2025-64593): “Meta pixel for WordPress” – Version 4.1.5: Use Logs with Enhanced Security

WP Activity Log is a powerful WordPress plugin designed to provide detailed, real-time logging of all activities across your WordPress sites and multisite networks. From user login attempts to changes in posts, plugins, themes, and settings, this plugin gives administrators full visibility into everything that happens on their websites.

Plugin Security Certification (PSC-2025-64589): “WP Log Manager” – Version 5.5.1: Use Logs with Enhanced Security

Plugin Security Certification (PSC-2025-64589): “WP Log Manager” – Version 5.5.1: Use Logs with Enhanced Security

WP Activity Log is a powerful WordPress plugin designed to provide detailed, real-time logging of all activities across your WordPress sites and multisite networks. From user login attempts to changes in posts, plugins, themes, and settings, this plugin gives administrators full visibility into everything that happens on their websites.

With its granular event tracking, WP Activity Log helps site owners improve security, accountability, compliance, and troubleshooting. Administrators can detect suspicious activity before it escalates, meet compliance standards such as GDPR and PCI DSS, and streamline user management with accurate records of who did what, when, and from where.

By ensuring every action is logged, WP Activity Log provides a transparent and secure environment, making it a vital tool for businesses, agencies, and security professionals managing WordPress-powered sites.

Plugin Security Certification (PSC-2025-64587): “PHP Compatibility Cheker” – Version 1.6.3: Use Automatic Update WP with Enhanced Security

Plugin Security Certification (PSC-2025-64587): “PHP Compatibility Cheker” – Version 1.6.3: Use Automatic Update WP with Enhanced Security

PHP Compatibility Checker is a WordPress plugin developed by WP Engine that helps site administrators and developers analyze their WordPress themes and plugins for compatibility with modern PHP versions.

As WordPress continues to evolve, maintaining compatibility with supported PHP versions is a crucial factor for both performance and security. Outdated PHP releases no longer receive security updates, leaving websites at risk of vulnerabilities. This plugin empowers users to safely transition to newer PHP versions (up to PHP 8.0) by identifying errors and warnings in their installed codebase.

The tool uses linting technology combined with Tide’s scanning infrastructure to analyze plugin and theme files. It generates detailed reports with file names, line numbers, and descriptions of incompatibilities. Additionally, it recommends plugin or theme updates if newer versions include PHP compatibility fixes.

CVE-2025-9111 – WPBOT – Stored XSS – POC

CVE-2025-9111 – WPBOT – Stored XSS – POC

WPBot is a WordPress plugin that provides an AI-powered chatbot for websites, enabling live chat support, lead generation, and data collection. It integrates with OpenAI, ChatGPT, and other LLM services, while also offering built-in automated support without external AI dependencies.

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in WPBot Lite that allows users to inject malicious scripts via the FAQ Builder, affecting users with sufficient access (such as contributors or admins reviewing FAQs). This vulnerability can lead to account compromise, data exfiltration, and site takeover.

Plugin Security Certification (PSC-2025-64586): “WP Downgrade” – Version 1.2.6: Use Automatic Update WP with Enhanced Security

Plugin Security Certification (PSC-2025-64586): “WP Downgrade” – Version 1.2.6: Use Automatic Update WP with Enhanced Security

WP Downgrade | Specific Core Version is a vital WordPress plugin that allows administrators to downgrade or update their WordPress Core to a specific release. Unlike the default WordPress update routine, which only installs the latest release, this plugin provides flexible control over Core updates, enabling users to remain on a previous secure version or selectively update to compatible releases.

This is particularly useful for sites relying on plugins or themes that are not yet compatible with the latest WordPress release. By forcing WordPress to recognize a chosen version as the latest, WP Downgrade simplifies updates while maintaining compatibility and stability.

With the new advanced option, users can manually adjust the download link, enabling tasks like language-specific core downloads or fetching releases from alternative sources—all without compromising security.

Plugin Security Certification (PSC-2025-64585): “Auto Image Attributes From Filename With Bulk Updater” – Version 6.0.6: Use Image SEO with Enhanced Security

Plugin Security Certification (PSC-2025-64585): “Auto Image Attributes From Filename With Bulk Updater” – Version 6.0.6: Use Image SEO with Enhanced Security

Auto Image Attributes From Filename With Bulk Updater (v4.4) is a powerful WordPress plugin designed to automate the generation of essential image attributes—Alt Text, Title, Caption, and Description—directly from image filenames. By restoring and enhancing features that WordPress deprecated in earlier versions, this plugin significantly boosts both SEO and website accessibility.

Properly defined image attributes not only improve Google, Yahoo, and Bing image search rankings, but also ensure compliance with accessibility standards by helping users with visual impairments understand the content of your images.

With its bulk updater, administrators can quickly optimize entire media libraries in a single click, saving valuable time while ensuring consistency across all images.

Plugin Security Certification (PSC-2025-64583): “String locator” – Version 2.6.7: Use Search locator with Enhanced Security

Plugin Security Certification (PSC-2025-64583): “String locator” – Version 2.6.7: Use Search locator with Enhanced Security

String Locator is a specialized WordPress plugin designed to help developers, administrators, and site managers quickly find and edit text strings within themes, plugins, and even WordPress core files. This tool eliminates the guesswork of locating hardcoded text by providing precise search results, including file paths, matching lines, and contextual previews.

The plugin also features in-browser editing, allowing you to make changes directly from the search results. Before saving, it runs a built-in consistency check that scans for unbalanced braces, brackets, and parentheses, reducing the risk of syntax errors and broken functionality. While not a substitute for full testing, this safeguard significantly minimizes common editing mistakes.

For maximum safety, it’s recommended to work on a staging site before deploying changes to production.

Plugin Security Certification (PSC-2025-64580): “AI Engine” – Version 3.0.9: Use AI with Enhanced Security

Plugin Security Certification (PSC-2025-64580): “AI Engine” – Version 3.0.9: Use AI with Enhanced Security

AI Engine is an advanced WordPress plugin designed to bridge the power of modern AI models (like GPT-4.1, Claude, Gemini, o4, and others) with the flexibility and usability of WordPress. Whether you’re aiming to build custom chatbots, generate content, translate articles, or automate content workflows, AI Engine provides a powerful and secure solution—all from within the WordPress dashboard.

With deep integrations, developer-ready APIs, and support for multiple AI providers, AI Engine allows website owners to build intelligent, interactive, and efficient websites that scale with their needs. Beyond just functionality, the plugin has undergone rigorous code-level inspection and has been certified with the Plugin Security Certification (PSC) from CleanTalk, confirming its secure development practices and strong protection measures.