WPIntell

secure-xml-rpc

Secure XML-RPC

More secure wrapper for the WordPress XML-RPC interface.

50
7.0K
3.7
0
2
2

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

39 / 72 rows with source links

54.2% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

33 rows with no attached evidence

0 rows have source counts but still need direct links.

Download Momentum

180 days
31 47 -34.0% 251

Related Opportunities

4 markets

Source Evidence

Open evidence explorer
mixed support · high severity · relevance 0.95
Confusion about calculating the Authorization header

Confusion about calculating the Authorization header: users show security, bugs, compatibility pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
I think all I need to do is compute and encode the header and pass it along to the server, but when I do so, I get an error that says username and password are invalid.
mixed support · high severity · relevance 0.94
I cannot configure the plugin

I cannot configure the plugin: users show security, missing feature, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
I cannot configure the plugin Hi, Thanks for making this plugin available.
mixed support · high severity · relevance 0.83
Donate link is broken

Donate link is broken: users show bugs, missing feature, support pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Donate link is broken The donate link for this plugin is broken, most likely a minus sign is missing, as secure-xmlrpc should read secure-xml-rpc .
complaint review · high severity · relevance 0.79
Secure fail ?

Secure fail ?: users show security pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
This plugin has been hacked on a client website… This plugin has been hacked on a client website…
complaint support · medium severity · relevance 0.75
Adding a app key

Adding a app key: users show support, setup pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Adding a app key Hi there , I want to add the blogpress app using your plugin , I have installed it and all is fine Except I can not see the page as per your screenshot or link which allows me to add the app ?
mixed support · medium severity · relevance 0.61
Error

Error: users show bugs pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Error I try to use the plugin with a remote Java library and get an error: Code: -32700 redstone.xmlrpc.XmlRpcFault: parse error.
praise review · medium severity · relevance 0.5
Must have when using WordPress XMLRPC API

Must have when using WordPress XMLRPC API: users show migration, setup pain that may indicate a product gap.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Must have when using WordPress XMLRPC API In general, it’s good that the WordPress XMLRPC API is enabled per default in order to allow more integrated Web platforms and software, but the username/password authentication mechanism makes a WordPress installation very vulnerable to brute force and dictionary attacks, and even primitive network sniffing if HTTPS
praise review · medium severity · relevance 0.38
Very useful plugin

Very useful plugin: praise conversation with limited structured signal.

Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Proof Blocked card complete trust and abuse-prevention operations Evidence linked to opportunity
Very useful plugin

Competitor Context

16 shown
Login by Auth0 weak incumbent · intel 82.3 · weakness 76.7
weak incumbent
stale update history below-average rating bugs support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Limit Login Attempts weak incumbent · intel 81.1 · weakness 71.7
weak incumbent
stale update history 22 collected complaint signal(s) support bugs 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
WPS Limit Login weak incumbent · intel 80.5 · weakness 71.8
weak incumbent
1 unresolved support thread(s) stale update history bugs missing feature 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Duo Two-Factor Authentication praise owner · intel 78.5 · weakness 70.7
praise owner
stale update history below-average rating support bugs 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test authentication lockouts, bot/spam defenses, risky access changes, and incident alerts
authLdap praise owner · intel 75.9 · weakness 66.6
praise owner
stale update history 15 collected complaint signal(s) support bugs 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test authentication lockouts, bot/spam defenses, risky access changes, and incident alerts
Simple LDAP Login praise owner · intel 75.5 · weakness 66.2
praise owner
stale update history 26 collected complaint signal(s) missing feature support 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test authentication lockouts, bot/spam defenses, risky access changes, and incident alerts
Keyring praise owner · intel 75.2 · weakness 65.9
praise owner
stale update history 13 collected complaint signal(s) bugs missing feature 2 source links Proof Blocked Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
Login for Google Apps weak incumbent · intel 74.6 · weakness 62.3
weak incumbent
stale update history 6 collected complaint signal(s) support bugs 2 source links Proof Blocked Evidence linked to opportunity
Buyer: membership site owners, agencies, and operations teams · Wedge: test SSO roles, protected content, SSO/login handoffs, and private-data exposure

Repeated Themes

0 shown

No repeated plugin-level themes have been generated yet.

Collected Signals

8 shown from 8 collected
complaint Secure fail ? (1 star) review · 2016-05-02T07:24:53+00:00 · high severity · authentication

Secure fail ?: users show security pain that may indicate a product gap.

Evidence: This plugin has been hacked on a client website… This plugin has been hacked on a client website…
security trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Error support · 2015-05-09T13:53:05+00:00 · medium severity · authentication

Error: users show bugs pain that may indicate a product gap.

Evidence: Error I try to use the plugin with a remote Java library and get an error: Code: -32700 redstone.xmlrpc.XmlRpcFault: parse error.
bugs value form trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
complaint Adding a app key support · 2014-11-05T23:35:08+00:00 · medium severity · authentication

Adding a app key: users show support, setup pain that may indicate a product gap.

Evidence: Adding a app key Hi there , I want to add the blogpress app using your plugin , I have installed it and all is fine Except I can not see the page as per your screenshot or link which allows me to add the app ?
support setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed I cannot configure the plugin support · 2014-10-04T19:40:53+00:00 · high severity · authentication

I cannot configure the plugin: users show security, missing feature, support pain that may indicate a product gap.

Evidence: I cannot configure the plugin Hi, Thanks for making this plugin available.
security missing feature support setup trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Donate link is broken support · 2014-08-16T21:24:04+00:00 · high severity · authentication

Donate link is broken: users show bugs, missing feature, support pain that may indicate a product gap.

Evidence: Donate link is broken The donate link for this plugin is broken, most likely a minus sign is missing, as secure-xmlrpc should read secure-xml-rpc .
bugs missing feature support trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Must have when using WordPress XMLRPC API (5 stars) review · 2014-08-16T20:14:56+00:00 · medium severity · authentication

Must have when using WordPress XMLRPC API: users show migration, setup pain that may indicate a product gap.

Evidence: Must have when using WordPress XMLRPC API In general, it’s good that the WordPress XMLRPC API is enabled per default in order to allow more integrated Web platforms and software, but the username/password authentication mechanism makes a WordPress installation very vulnerable to brute force and dictionary attacks, and even primitive network sniffing if HTTPS
migration setup easy form trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
mixed Confusion about calculating the Authorization header support · 2014-01-11T22:20:19+00:00 · high severity · authentication

Confusion about calculating the Authorization header: users show security, bugs, compatibility pain that may indicate a product gap.

Evidence: I think all I need to do is compute and encode the header and pass it along to the server, but when I do so, I get an error that says username and password are invalid.
security bugs compatibility missing feature trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts
praise Very useful plugin (5 stars) review · 2014-01-11T21:40:23+00:00 · medium severity · authentication

Very useful plugin: praise conversation with limited structured signal.

Evidence: Very useful plugin
trust and abuse-prevention operations Proof Blocked card complete Evidence linked to opportunity
Buyer: site owners, agencies, and maintenance teams · Wedge: test security lockouts, bot/spam defenses, risky access changes, and incident alerts