
OutsourcingVN Change category name Security & Risk Analysis
wordpress.org/plugins/change-category-nameMajor features of this plugin include * Add text before or after current post title * Select category, tag or taxonomy to change
Is OutsourcingVN Change category name Safe to Use in 2026?
Generally Safe
Score 85/100OutsourcingVN Change category name has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'change-category-name' plugin version 1.0.0 demonstrates a strong adherence to secure coding practices based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, or unescaped output signals a well-developed and conscientious approach to security. The lack of file operations and external HTTP requests further minimizes the attack surface and potential for remote code execution or data exfiltration. The plugin also shows no recorded vulnerability history, suggesting a history of secure development and maintenance.
However, the analysis reveals a complete lack of security checks for its entry points, including AJAX handlers, REST API routes, shortcodes, and cron events. This presents a significant concern. While the static analysis did not identify any immediately exploitable issues like unsanitized taint flows or dangerous functions, the absence of any authentication or capability checks means that any future functionality introduced without proper security measures could be easily abused by unauthenticated users. The total absence of nonce checks and capability checks is a critical oversight, leaving all entry points potentially vulnerable to CSRF attacks or privilege escalation if any sensitive operations are performed.
In conclusion, while the plugin's current code is commendably clean in terms of direct vulnerabilities, the complete lack of security controls on its entry points is a substantial weakness. This architectural flaw means that even minor additions of functionality could introduce critical vulnerabilities. The plugin's strength lies in its clean core code, but its major weakness is its unprotected attack surface, which requires immediate attention.
Key Concerns
- No nonce checks on any entry points
- No capability checks on any entry points
- Zero unprotected entry points identified, but security checks are absent
OutsourcingVN Change category name Security Vulnerabilities
OutsourcingVN Change category name Release Timeline
OutsourcingVN Change category name Code Analysis
Output Escaping
OutsourcingVN Change category name Attack Surface
WordPress Hooks 2
Maintenance & Trust
OutsourcingVN Change category name Maintenance & Trust
Maintenance Signals
Community Trust
OutsourcingVN Change category name Alternatives
Change Mail Sender
cb-change-mail-sender
Easily change the default WordPress from email name and from email address.
Easy Username Updater
username-updater
A plugin to change registered username and display name.
WP Change Email Sender
wp-change-email-sender
Easily change WordPress default mail sender name and email address
Rename wp-admin login
rename-wp-admin-login
Rename wp-admin login* is a plugin that allows us to rename wp-admin login URL to anything you want
Change Username
change-username
Change usernames of your WordPress users effectively.
OutsourcingVN Change category name Developer Profile
4 plugins · 10 total installs
How We Detect OutsourcingVN Change category name
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
btnbtn-primaryid="new_settings_plugin_offset"id="new_settings_plugin_before"id="new_settings_plugin_after"id="new_settings_plugin_list_taxonomy"