Better Plugin Recommendations Security & Risk Analysis

wordpress.org/plugins/better-plugin-recommendations

There are so many plugins out there. Knowing which ones to choose can be really hard. Let us help.

10 active installs v1.0.0 PHP + WP 3.7+ Updated Apr 20, 2017
plugins
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Better Plugin Recommendations Safe to Use in 2026?

Generally Safe

Score 85/100

Better Plugin Recommendations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'better-plugin-recommendations' v1.0.0 plugin exhibits a strong security posture based on the static analysis. The complete absence of dangerous functions, raw SQL queries, unescaped output, file operations, and taint flows with unsanitized paths is a significant positive indicator. The fact that all SQL queries utilize prepared statements and all detected outputs are properly escaped demonstrates good development practices. The plugin also makes external HTTP requests, which is a common and often necessary feature, and the analysis does not suggest these are being handled insecurely. The vulnerability history being completely clear further reinforces this positive assessment, indicating a history of secure development or diligent patching.

However, the analysis also reveals some areas that could be improved. The plugin has no capability checks or nonce checks implemented across any of its identified entry points. While the static analysis found no unprotected entry points, the absence of these fundamental WordPress security mechanisms means that any future additions or modifications to the code could inadvertently introduce vulnerabilities. The plugin also has two external HTTP requests, and while not flagged as a risk here, the security of these requests should be continuously monitored for potential vulnerabilities. In conclusion, the plugin is currently in a very good security state with no known vulnerabilities and a clean code analysis. The primary area for improvement lies in strengthening its defense-in-depth by incorporating capability and nonce checks, even if no immediate risks are apparent.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Better Plugin Recommendations Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Better Plugin Recommendations Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Better Plugin Recommendations Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0
Attack Surface

Better Plugin Recommendations Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterinstall_plugins_tabsbetter-plugin-recommendations.php:18
filterplugins_apibetter-plugin-recommendations.php:31
filtergettextbetter-plugin-recommendations.php:98
Maintenance & Trust

Better Plugin Recommendations Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedApr 20, 2017
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Better Plugin Recommendations Developer Profile

Nick Hamze

2 plugins · 60 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Better Plugin Recommendations

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/api/plugin-recommendations
FAQ

Frequently Asked Questions about Better Plugin Recommendations