
AutoCHMOD Security & Risk Analysis
wordpress.org/plugins/autochmodProtect folders and files from unhautorized changes managing filesystem permissions.
Is AutoCHMOD Safe to Use in 2026?
Generally Safe
Score 85/100AutoCHMOD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The autochmod plugin version 0.5.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and shows no known critical or high-severity vulnerabilities in its history. The static analysis also indicates no dangerous functions, external HTTP requests, or bundled libraries, which are all positive signs. However, there are significant areas for concern. The lack of any nonce checks or capability checks across all identified entry points (cron events in this case) is a major weakness, leaving these functions vulnerable to unauthorized execution. Furthermore, a substantial portion of the output (46%) is not properly escaped, presenting a risk of Cross-Site Scripting (XSS) vulnerabilities if the unescaped output originates from user-controlled data. The absence of taint analysis results is also notable, as it limits the ability to fully assess risks related to data flow and sanitization.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Significant amount of unescaped output
AutoCHMOD Security Vulnerabilities
AutoCHMOD Code Analysis
Output Escaping
AutoCHMOD Attack Surface
WordPress Hooks 10
Scheduled Events 2
Maintenance & Trust
AutoCHMOD Maintenance & Trust
Maintenance Signals
Community Trust
AutoCHMOD Alternatives
Permissions & Security Audit
permissions-security-audit
Permissions & Security Audit is a plugin that runs a series of tests to check common security issues with the following areas:
WPFront User Role Editor
wpfront-user-role-editor
Easily allows you to manage WordPress user roles. You can create, edit, delete and manage capabilities, also copy existing roles.
Restricted Site Access
restricted-site-access
Limit access to visitors who are logged in or allowed by IP addresses. Includes many options for handling blocked visitors.
Security Header Generator
security-header-generator
This plugin generates the proper security HTTP response headers to keep your site secured.
File Permissions & Size Check
wp-file-permission-check
Simple plugin that checks your WordPress install and shows your file permissions, size, and last modified date.
AutoCHMOD Developer Profile
2 plugins · 40 total installs
How We Detect AutoCHMOD
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autochmod/graphic/opened.png/wp-content/plugins/autochmod/graphic/closed.pngHTML / DOM Fingerprints
id="autochmod_min"id="autochmod_sec"id="autochmodlockicon"window.setInterval