
Additional Plugins Descriptions Security & Risk Analysis
wordpress.org/plugins/additional-plugins-descriptionsAllows you to write additional descriptions for plugins.
Is Additional Plugins Descriptions Safe to Use in 2026?
Generally Safe
Score 85/100Additional Plugins Descriptions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "additional-plugins-descriptions" v0.1.0 plugin exhibits a concerning security posture primarily due to its limited attack surface and a single unprotected AJAX handler. While it demonstrates good practices by using prepared statements for SQL queries and properly escaping all outputs, the presence of the "unserialize" function is a significant red flag. This function is notoriously dangerous if not handled with extreme care, as it can lead to remote code execution if it processes untrusted user input. The lack of nonce checks and capability checks on its AJAX endpoint further amplifies this risk, allowing any authenticated user to potentially trigger the "unserialize" function with crafted input.
Despite the absence of known vulnerabilities (CVEs) and any recorded critical or high-severity taint flows, the static analysis reveals foundational security weaknesses. The single unprotected AJAX entry point coupled with a dangerous function presents a clear and present risk. The plugin's vulnerability history of "none recorded" is a positive sign, but it does not negate the inherent dangers identified in the code. Therefore, while the plugin doesn't have a history of breaches, its current implementation is risky and requires immediate attention, especially concerning the handling of serialized data.
Key Concerns
- Unprotected AJAX handler
- Use of unserialize()
- Missing nonce check on AJAX
- Missing capability check on AJAX
Additional Plugins Descriptions Security Vulnerabilities
Additional Plugins Descriptions Code Analysis
Dangerous Functions Found
Output Escaping
Additional Plugins Descriptions Attack Surface
AJAX Handlers 1
WordPress Hooks 3
Maintenance & Trust
Additional Plugins Descriptions Maintenance & Trust
Maintenance Signals
Community Trust
Additional Plugins Descriptions Alternatives
WPCore Plugin Manager
wpcore
Create plugin collections and install them in one click on any WordPress site.
One Click Close Comments
one-click-close-comments
Conveniently close or open comments for a post or page with one click from the admin listing of posts.
Relative URL
relative-url
Relative URL applies wp_make_link_relative function to links to convert them to relative URLs.
Hide Plugins
hide-plugins
Hide installed plugins from clients and other admin users.
Plugin Report
plugin-report
A WordPress plugin that provides detailed information about currently installed plugins.
Additional Plugins Descriptions Developer Profile
1 plugin · 0 total installs
How We Detect Additional Plugins Descriptions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/additional-plugins-descriptions/additional-plugins-descriptions.js/wp-content/plugins/additional-plugins-descriptions/additional-plugins-descriptions.jsadditional-plugins-descriptions/additional-plugins-descriptions.js?ver=HTML / DOM Fingerprints
apd-tableapd-editableapd-editable-temporaryapd-editable-permanentяваскриптвыводить доп информацию под стандартным описанием плагинасохранять изменённое описание плагинапри удалении любого плагина удалять и временное описание для него+7 moredata-plugin_namecontenteditable/wp-admin/admin-ajax.php