Additional Options and Tweaks Security & Risk Analysis

wordpress.org/plugins/additional-wp-tweaks-options

Adds extra wordpress options, which are not shown in stock WordPress Dashboard [ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 𝙗𝙮 𝙋𝙪𝙫𝙤𝙭 ]

10 active installs v1.27.1 PHP + WP 6.0+ Updated Jan 11, 2025
dashboardextraoptionssettingstweaks
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Additional Options and Tweaks Safe to Use in 2026?

Generally Safe

Score 92/100

Additional Options and Tweaks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "additional-wp-tweaks-options" plugin version 1.27.1 presents a mixed security posture. On the positive side, the plugin exhibits a low attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication. Furthermore, the vast majority of SQL queries utilize prepared statements, and there is a reasonable number of nonce and capability checks in place, suggesting some awareness of WordPress security best practices.

However, several concerns warrant attention. The presence of 16 dangerous functions, including `set_time_limit`, `ini_set`, and `unserialize`, raises red flags. `unserialize` in particular is a known vector for remote code execution if used with untrusted input. The taint analysis revealing 7 flows with unsanitized paths, even without a critical or high severity finding in this specific analysis, indicates a potential for unexpected behavior or vulnerabilities if input is not strictly validated. The fact that only 56% of outputs are properly escaped is also concerning, as it opens the door to cross-site scripting (XSS) vulnerabilities.

The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a strong positive indicator, suggesting a commitment to maintaining a secure codebase. However, the presence of potentially risky functions and unsanitized flows means that even without past vulnerabilities, future risks are not entirely eliminated. The plugin's strengths lie in its minimal attack surface and good SQL practices, but its weaknesses lie in the use of dangerous functions, potential for unsanitized input to lead to vulnerabilities, and insufficient output escaping.

Key Concerns

  • High number of dangerous functions
  • Unsanitized paths in taint flows
  • Low percentage of properly escaped output
Vulnerabilities
None known

Additional Options and Tweaks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Additional Options and Tweaks Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Additional Options and Tweaks Code Analysis

Dangerous Functions
16
Raw SQL Queries
5
55 prepared
Unescaped Output
77
99 escaped
Nonce Checks
5
Capability Checks
2
File Operations
19
External Requests
4
Bundled Libraries
0

Dangerous Functions Found

set_time_limitset_time_limit(min(10000, $this->opts['maximum_execution_time_limit']));index.php:473
ini_setini_set("xdebug.var_display_max_children", '-1');library.php:66
ini_setini_set("xdebug.var_display_max_data", '10000');library.php:67
ini_setini_set("xdebug.var_display_max_depth", '-1');library.php:68
ini_setini_set('session.cookie_httponly', 1);library.php:134
ini_setini_set('post_max_size', $this->upload_max_limit.'M'); ini_set('upload_max_filesize', upload_max_limlibrary.php:148
ini_setini_set('post_max_size', $this->upload_max_limit.'M'); ini_set('upload_max_filesize', upload_max_limlibrary.php:148
ini_setini_set('post_max_size', $this->upload_max_limit.'M'); ini_set('upload_max_filesize', upload_max_limlibrary.php:148
ini_setreturn ini_set('max_execution_time', $seconds); //stackoverflow.com/questions/8914257library.php:492
ini_setreturn ini_set('memory_limit', $new_limit . 'M');library.php:508
ini_setini_set("opcache.enable", 0);library.php:2243
unserializeif ( @unserialize($serialized_string) !== false ) return $serialized_string;library.php:3813
ini_setini_set('display_errors', 1);library.php:4562
ini_setini_set('display_startup_errors', 1);library.php:4563
ini_setini_set("log_errors", 1);library.php:4572
ini_setini_set("error_log", $path ? $path : $_SERVER['DOCUMENT_ROOT']."/zzz___php-my-errors_".$this->my_sitlibrary.php:4573

SQL Query Safety

92% prepared60 total queries

Output Escaping

56% escaped176 total outputs
Data Flows · Security
7 unsanitized

Data Flow Analysis

10 flows7 with unsanitized paths
force_redirect_to_https (library.php:103)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Additional Options and Tweaks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 115
filterupload_size_limitindex.php:469
actionwp_loadedindex.php:510
actionshutdownindex.php:520
actionedit_category_form_fieldsindex.php:525
actionedited_categoryindex.php:537
actionthe_excerptindex.php:547
actionthe_excerpt_rssindex.php:548
actionthe_excerpt_feedindex.php:549
actionthe_contentindex.php:551
actionthe_content_rssindex.php:552
actionthe_content_feedindex.php:553
filterbody_classindex.php:565
filteradmin_body_classindex.php:566
actionadmin_headindex.php:590
actionwp_headindex.php:591
actionrest_api_initindex.php:595
filterrest_authentication_errorsindex.php:602
filterrest_endpointsindex.php:615
filterauto_core_update_send_emailindex.php:627
filterauto_plugin_update_send_emailindex.php:630
filterauto_theme_update_send_emailindex.php:631
actionadmin_headindex.php:636
actionwp_headindex.php:638
actioninitindex.php:644
filtertiny_mce_pluginsindex.php:656
filterwp_mail_fromindex.php:663
filterwp_mail_from_nameindex.php:664
filterwp_mail_content_typeindex.php:665
actionwp_footerindex.php:683
actioninitindex.php:697
filtershow_admin_barindex.php:699
filteradmin_titleindex.php:701
actionadmin_xml_nsindex.php:703
actioninitindex.php:712
filterupload_mimesindex.php:744
filterwp_check_filetype_and_extindex.php:765
actionwp_headindex.php:781
filterexcerpt_moreindex.php:789
filterexcerpt_lengthindex.php:793
filterauth_cookie_expirationindex.php:797
actionpre_get_postsindex.php:816
actionpre_get_postsindex.php:834
filtermanage_posts_columnsindex.php:860
filtermanage_pages_columnsindex.php:861
actionmanage_posts_custom_columnindex.php:864
actionmanage_pages_custom_columnindex.php:865
actionadmin_headindex.php:868
actionadmin_initindex.php:894
actionwp_headindex.php:918
filterthe_contentindex.php:925
filterthe_excerptindex.php:926
filterthe_titleindex.php:927
filterget_the_contentindex.php:928
filterget_the_excerptindex.php:929
filterget_the_titleindex.php:930
filterthe_content_rssindex.php:935
filterthe_excerpt_rssindex.php:936
filterthe_title_rssindex.php:937
filterthe_content_feedindex.php:938
filterthe_excerpt_feedindex.php:939
filterthe_title_feedindex.php:940
filterget_the_content_rssindex.php:941
filterget_the_excerpt_rssindex.php:942
filterget_the_title_rssindex.php:943
filterget_the_content_feedindex.php:944
filterget_the_excerpt_feedindex.php:945
filterget_the_title_feedindex.php:946
filterwp_trim_wordsindex.php:948
actionpre_get_postsindex.php:980
filterget_search_formindex.php:991
actionadmin_headindex.php:1009
actionwp_headindex.php:1014
actionwp_footerindex.php:1021
actionwp_footerindex.php:1025
filterthe_contentindex.php:1031
filterget_the_contentindex.php:1032
actionwp_footerindex.php:1033
filterparse_queryindex.php:1068
actioninitindex.php:1113
actionpre_get_postsindex.php:1114
actionwp_admin_noticeindex.php:1158
filterpre_ksesindex.php:1161
actionwp_headlibrary.php:4768
actionadmin_headlibrary.php:4769
actionwp_enqueue_scriptslibrary_wp.php:73
actionadmin_enqueue_scriptslibrary_wp.php:74
actionadmin_footerlibrary_wp.php:148
actioninitlibrary_wp.php:163
actionadmin_initlibrary_wp.php:210
filtermce_external_pluginslibrary_wp.php:212
filtermce_buttons_2library_wp.php:213
filtertiny_mce_versionlibrary_wp.php:215
actionwplibrary_wp.php:231
actionplugins_loadedlibrary_wp.php:540
actionwplibrary_wp.php:550
actionwp_footerlibrary_wp.php:700
actioninitlibrary_wp.php:711
actionwp_loadedlibrary_wp.php:854
actionshutdownlibrary_wp.php:859
actioninitlibrary_wp.php:1732
actionadmin_headlibrary_wp.php:1743
actioncurrent_screenlibrary_wp.php:1744
actionwplibrary_wp.php:1753
filterupload_mimeslibrary_wp.php:1759
filterwp_handle_uploadlibrary_wp.php:1760
actioninitlibrary_wp.php:1822
actionnetwork_admin_menulibrary_wp.php:1912
actionadmin_menulibrary_wp.php:1914
actionactivated_pluginlibrary_wp.php:1916
actionnetwork_admin_noticeslibrary_wp.php:2103
actionadmin_noticeslibrary_wp.php:2104
filterwp_php_error_messagelibrary_wp.php:2187
actionwp_footerlibrary_wp.php:2375
filterwidget_textlibrary_wp.php:2399
filtersite_transient_update_pluginslibrary_wp.php:3266
Maintenance & Trust

Additional Options and Tweaks Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 11, 2025
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Additional Options and Tweaks Developer Profile

Puvox Software

19 plugins · 51K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
540 days
View full developer profile
Detection Fingerprints

How We Detect Additional Options and Tweaks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/additional-wp-tweaks-options/admin/css/general.css/wp-content/plugins/additional-wp-tweaks-options/admin/css/pages.css/wp-content/plugins/additional-wp-tweaks-options/admin/css/posttypes.css/wp-content/plugins/additional-wp-tweaks-options/admin/css/settings.css/wp-content/plugins/additional-wp-tweaks-options/admin/css/users.css/wp-content/plugins/additional-wp-tweaks-options/admin/js/general.js/wp-content/plugins/additional-wp-tweaks-options/admin/js/pages.js/wp-content/plugins/additional-wp-tweaks-options/admin/js/posttypes.js+2 more
Version Parameters
additional-wp-tweaks-options/admin/css/general.css?ver=additional-wp-tweaks-options/admin/css/pages.css?ver=additional-wp-tweaks-options/admin/css/posttypes.css?ver=additional-wp-tweaks-options/admin/css/settings.css?ver=additional-wp-tweaks-options/admin/css/users.css?ver=additional-wp-tweaks-options/admin/js/general.js?ver=additional-wp-tweaks-options/admin/js/pages.js?ver=additional-wp-tweaks-options/admin/js/posttypes.js?ver=additional-wp-tweaks-options/admin/js/settings.js?ver=additional-wp-tweaks-options/admin/js/users.js?ver=

HTML / DOM Fingerprints

CSS Classes
additional-wp-tweaks-options-containeradditional-wp-tweaks-options-settingsadditional-wp-tweaks-options-generaladditional-wp-tweaks-options-pagesadditional-wp-tweaks-options-posttypesadditional-wp-tweaks-options-usersadditional_wp_tweaks_options_search_highlight
HTML Comments
<!-- Begin Puvox.software --><!-- End Puvox.software -->
Data Attributes
data-puvox-optionsdata-puvox-settingsdata-puvox-page-settingsdata-puvox-posttype-settingsdata-puvox-user-settings
JS Globals
AdditionalWpTweaksOptionsadditionalWpTweaksOptionspuvox_settings
FAQ

Frequently Asked Questions about Additional Options and Tweaks