WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: prevent-xss-vulnerability (Used by 217 domains)

Prevent XSS Vulnerability

πŸ‘€ Sami Ahmed Siddiqui πŸ“¦ v2.1.0 πŸ”— Plugin Homepage

This plugin helps safeguard your website against two common types of Cross-Site Scripting (XSS) vulnerabilities:

  • Reflected XSS: This happens when harmful scripts are hidden in a website’s URL. If a user clicks a link with such a script, it can run in their browser, potentially stealing their data or taking control of their system.
  • Self-XSS: This occurs when a user’s own input on your website is displayed back to them in an unsafe way, allowing malicious scripts to run in their browser.

This plugin provides several layers of protection:

Blocking: When active, the plugin checks URLs for specific characters. If it finds any of these characters in the URL, it redirects the user to prevent a potential XSS attack. You can customize which characters to block or allow.

  • Opening Round Bracket (
  • Closing Round Bracket )
  • Less than Sign <
  • Greater than Sign >
  • Opening Square Bracket [
  • Closing Square Bracket ]
  • Opening Curly Bracket {
  • Pipe or Vertical Bar |
  • Closing Curly Bracket }

Encoding: For an extra layer of security, the plugin encodes certain characters found in URL parameters. This stops harmful code from running, even if it’s present in the URL. You can also choose to exclude specific parameters from being encoded.

  • Exclamation Mark !
  • Double Quotation "
  • Single Quotation '
  • Opening Round Bracket (
  • Closing Round Bracket )
  • Asterisk Sign *
  • Less than Sign <
  • Greater than Sign >
  • Grave Accent β€œ`
  • Cap Sign ^
  • Opening Square Bracket [
  • Closing Square Bracket ]
  • Opening Curly Bracket {
  • Pipe or Vertical Bar |
  • Closing Curly Bracket }

Escaping HTML in $_GET: This plugin automatically makes HTML characters safe within the $_GET variable. This is vital if your website pulls data from URLs and displays it as part of your web page. It helps prevent malicious scripts from being injected through user-provided input.

Important Notes:

  • After activating the plugin, thoroughly test your website forms, especially if you use WooCommerce. Make sure the plugin doesn’t interfere with your shopping cart and checkout processes.
  • We welcome bug reports for this plugin on GitHub: https://github.com/samiahmedsiddiqui/prevent-xss-vulnerability/issues. Please remember that GitHub is for bug reports only, not general support.

By using this plugin and following these recommendations, you can significantly improve your website’s defense against XSS attacks.

DomainExposuresHeadersLast Checked
g*v*h*p.com βœ… F 2026-04-26 18:04:12
d*s*r*b*t*d*q*.com βœ… B 2026-04-26 17:03:40
1*2*w*l*e.nl βœ… C 2026-04-26 13:09:43
1*2*e*w*l*e.nl βœ… C 2026-04-26 13:09:43
1*2*a*e*i*g*n.nl βœ… C 2026-04-26 13:09:43
1*2*e*n*n*a*l.nl βœ… C 2026-04-26 13:09:43
1*2*e*h*d*l.nl βœ… C 2026-04-26 13:09:43
1*2*a*l*i.nl βœ… C 2026-04-26 13:09:43
1*2*c*i*d*m.nl βœ… C 2026-04-26 13:09:43
1*2*c*e*p*n*e*l.nl βœ… C 2026-04-26 13:09:43
1*2*o*t*r*a*.nl βœ… C 2026-04-26 13:09:43
1*2*i*d*r*e*k.nl βœ… C 2026-04-26 13:09:43
1*2*v*r*j*s*l.nl βœ… C 2026-04-26 13:09:43
1*2*i*k*r*.nl βœ… C 2026-04-26 13:09:43
1*2*e*p*l.nl βœ… C 2026-04-26 13:09:43
1*2*e*y*t*d.nl βœ… C 2026-04-26 13:09:43
1*2*n*e*l*.nl βœ… C 2026-04-26 13:09:43
1*2*i*v*r*u*.nl βœ… C 2026-04-26 13:09:43
1*2*a*d*r*i*k.nl βœ… C 2026-04-26 13:09:43
1*2*l*v*l*n*.nl βœ… C 2026-04-26 13:09:43
1*2*m*e*.nl βœ… C 2026-04-26 13:09:43
1*2*i*d*o*e*.nl βœ… C 2026-04-26 13:09:43
1*2*d*.nl βœ… C 2026-04-26 13:09:43
1*2*r*n*h*.nl βœ… C 2026-04-26 13:09:43
1*2*o*t*n*h*m.nl βœ… C 2026-04-26 13:09:43
1*2*u*s*h*t*n.nl βœ… C 2026-04-26 13:09:43
1*2*a*n*v*l*.nl βœ… C 2026-04-26 13:09:43
1*2*s*e*.nl βœ… C 2026-04-26 13:09:43
1*2*r*h*m.nl βœ… C 2026-04-26 13:09:43
1*2*p*l*o*r*.nl βœ… C 2026-04-26 13:09:43
1*2*m*r*f*o*t.nl βœ… C 2026-04-26 13:09:43
1*2*m*t*r*a*.nl βœ… C 2026-04-26 13:09:43
e*e*s*o*t*a*l.co.uk βœ… A 2026-04-26 05:32:23
t*e*u*u*e*e*l*h*a*e.org βœ… F 2026-04-26 01:34:17
c*m*l*n.in βœ… A 2026-04-26 01:15:05
d*s*r*b*t*d*q*.org βœ… B 2026-04-25 22:16:56
e*r*u*g*o*.in βœ… F 2026-04-25 22:10:26
f*e*t*s*n*n*e*t*e*t.com βœ… C 2026-04-25 21:09:31
v*l*s*a*e*a*.com βœ… D 2026-04-25 11:47:49
g*d*c*n*d*.com βœ… A 2026-04-25 07:20:34
a*s*g*m*n*h*l*o*t*l.com βœ… F 2026-04-25 00:51:04
p*b*i*s*e*d*o*u*.net βœ… F 2026-04-24 20:44:23
e*c*m.gov.in βœ… B 2026-04-24 19:40:57
g*o*i*.org.il (WP 6.9.4) βœ… F 2026-04-24 18:12:36
o*v*r*p*o*o*.com βœ… F 2026-04-24 17:07:06
g*s*e*.pl βœ… A 2026-04-24 16:23:02
m*t*o*z.com (WP 6.9.4) βœ… F 2026-04-24 15:22:10
l*p*k*o*m*d.com (WP 6.4.8) ⚠️ C 2026-04-24 14:58:13
m*b*l*e*e*t*p*.com βœ… D 2026-04-24 05:51:05
c*r*o.airarabia.com (WP 6.9) βœ… A 2026-04-24 00:46:26
a*i*o*y*w*b.agency βœ… A 2026-04-23 19:24:22
u*e*h*c*l*s*o*e.com βœ… A 2026-04-23 14:23:46
k*t*l*e*u*a*e*.com βœ… F 2026-04-23 11:41:52
s*c*l*a*-*l*t*i*g.com (WP 6.9.4) βœ… F 2026-04-23 02:51:33
s*p*w.pl βœ… D 2026-04-22 14:41:37
a*t*e*-*e*i*e.com βœ… D 2026-04-22 07:42:00
h*l*a*s*a*l*u*i*e*s*o*u*i*n*.com βœ… C 2026-04-21 17:21:21
h*l*a*c*m*u*i*y.com βœ… C 2026-04-21 17:21:19
h*l*a*c*r*e*s.com βœ… C 2026-04-21 17:21:19
h*l*a*.com βœ… C 2026-04-21 17:21:19
m*p*m*l*p*l*k*.pl βœ… A 2026-04-20 20:13:06
c*s*d*m*e*a.pt βœ… F 2026-04-20 18:17:27
h*t*s*e.com βœ… C 2026-04-20 18:09:15
m*m*l*r*.com βœ… C 2026-04-20 11:25:11
w*s*o*m*n*f*c*u*i*g.com βœ… F 2026-04-19 23:33:54
v*a*d.com βœ… D 2026-04-19 11:48:21
h*n*u*s.cabinetoffice.gov.uk βœ… F 2026-04-19 10:26:47
s*c.unistra.fr (WP 6.9.4) βœ… A 2026-04-19 02:00:40
h*d*n*m.com βœ… F 2026-04-18 21:35:40
g*.eventmobi.com βœ… D 2026-04-18 16:04:40
h*l*a*g*o*t*v*n*u*e*.com βœ… C 2026-04-17 08:30:27
h*l*a*g*o*t*c*p*t*l.com βœ… C 2026-04-17 08:30:27
d*u*s*a*.com βœ… D 2026-04-16 18:34:10
t*k*o*a*i*e.com.br βœ… D 2026-04-15 20:25:59
s*l*h*l*.ac.uk βœ… B 2026-04-15 18:37:57
z*b*i*m.com βœ… F 2026-04-15 13:48:42
r*d*u*i*.com βœ… A 2026-04-15 11:21:20
o*t*n*t*a*e*s*l*t*o*s.com βœ… A 2026-04-15 08:34:26
o*t*n*-*a*i*g.com βœ… A 2026-04-15 08:31:32
b*s*h*s*s.com (WP 6.9.4) βœ… A 2026-04-14 23:26:57
k*l*p*r*a*k.com βœ… C 2026-04-14 13:03:51
e*e*t*m*b*.com βœ… D 2026-04-14 07:58:42
n*i*u*i.cn βœ… D 2026-04-14 07:02:43
e*e*t*o*i.com βœ… D 2026-04-14 06:34:15
t*o*z*e*i*g*o*p.com (WP 6.9.4) βœ… F 2026-04-13 12:25:25
t*o*z*n*i*.com (WP 6.9.4) βœ… F 2026-04-13 12:25:24
t*o*z*n*m*t*o*i*d*a.com (WP 6.9.4) βœ… F 2026-04-13 12:25:24
a*a*i*g*v*n*a*p*.com βœ… D 2026-04-13 11:31:11
t*n*h*m*t*s*i*r*e*.com βœ… F 2026-04-13 07:49:06
j*h*l*i*r*.com βœ… C 2026-04-13 06:09:12
d*i*y*o*e*f*u*c*.com βœ… C 2026-04-13 05:12:50
n*1.nickifaulk.com (WP 6.9.4) βœ… F 2026-04-13 03:50:40
y*s*l*b*l.com βœ… C 2026-04-12 02:18:16
a*c*.org.il βœ… F 2026-04-12 00:12:26
c*s*o*p*r*a*i*k*.com βœ… F 2026-04-11 23:17:38
a*p*s*o*o*t*m*i.com βœ… C 2026-04-11 22:55:50
c*r*d*b*.com (WP 6.7.5) βœ… F 2026-04-11 12:37:40
c*e.org.il βœ… F 2026-04-11 00:15:23
n*s*p*l*a*c*.com βœ… F 2026-04-10 13:23:09
s*a*e*o*t*n*.com βœ… F 2026-04-10 05:00:22

Top 50 Plugins

Plugin Count
elementor 2,763,705
contact-form-7 2,452,730
elementor-pro 1,546,184
woocommerce 1,302,279
revslider 924,221
js_composer 598,061
jetpack 497,596
wp-rocket 434,118
essential-addons-for-elementor-lite 415,356
header-footer-elementor 362,082
gutenberg-core 352,678
elementskit-lite 339,433
instagram-feed 313,147
google-analytics-for-wordpress 312,225
gravityforms 304,500
google-site-kit 301,253
complianz-gdpr 294,888
cookie-law-info 292,598
wpforms-lite 257,097
sitepress-multilingual-cms 254,170
astra-sites 250,354
bluehost-wordpress-plugin 241,097
litespeed-cache 224,187
gtranslate 183,504
coblocks 177,561
cookie-notice 169,990
gutenberg 162,533
the-events-calendar 149,080
popup-maker 140,281
premium-addons-for-elementor 135,669
astra-addon 134,465
bb-plugin 133,678
mailchimp-for-wp 132,167
LayerSlider 128,805
wp-smushit 127,445
custom-fonts 122,509
tablepress 120,972
creame-whatsapp-me 120,412
pro-elements 118,018
click-to-chat-for-whatsapp 115,581
woocommerce-gateway-stripe 112,342
duracelltomi-google-tag-manager 112,338
cleantalk-spam-protect 109,251
smart-slider-3 107,093
akismet 106,186
pixelyoursite 104,954
megamenu 103,736
fusion-builder 103,281
honeypot 102,819
royal-elementor-addons 102,709

Top 50 Themes

Theme Count
hello-elementor 881,464
astra 738,280
Divi 721,754
pub 234,524
generatepress 165,845
flatsome 165,155
Avada 155,165
h4 146,424
oceanwp 121,209
kadence 107,389
enfold 90,891
salient 88,032
bb-theme 85,966
twentytwentyfour 83,177
blocksy 81,531
twentytwentyfive 80,531
cocoon-master 76,912
betheme 72,668
twentyseventeen 70,094
woodmart 61,800
dt-the7 59,456
neve 52,307
twentytwentyone 45,266
bridge 44,342
swell 41,011
Avada-Child-Theme 39,544
twentytwenty 38,803
lightning 38,190
twentytwentythree 37,772
gox 37,336
bricks 31,465
Impreza 31,349
Newspaper 29,587
twentytwentytwo 28,978
epik-redesign 24,437
extendable 23,860
storefront 23,806
pro 23,711
uncode 23,090
yith-wonder 22,986
twentysixteen 22,667
sydney 21,681
themify-ultra 21,308
twentyfifteen 19,591
Total 19,472
porto 17,998
hestia 17,276
thrive-theme 16,469
yootheme 15,971
jupiter 15,762