
Changeloger – Changelog, Release Notes & User Feedback Security & Risk Analysis
wordpress.org/plugins/changelogerThe all-in-one changelog, release notes, public roadmap, and user feedback plugin for WordPress. Beautiful visual designs out of the box.
Is Changeloger – Changelog, Release Notes & User Feedback Safe to Use in 2026?
Generally Safe
Score 100/100Changeloger – Changelog, Release Notes & User Feedback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "changeloger" plugin v1.7.0 presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and a high percentage of properly escaped outputs. The absence of known vulnerabilities (CVEs) and a clean vulnerability history is also a significant strength, suggesting the developers have historically prioritized security. However, the static analysis reveals several areas of concern.
A notable risk lies in the plugin's attack surface. With 13 REST API routes, a substantial 7 of these lack permission callbacks, meaning they are accessible without proper authentication or authorization checks. This creates a significant entry point for potential attackers. Furthermore, the presence of the "unserialize" function is a red flag, as it can be a source of critical vulnerabilities if not handled with extreme care, especially when dealing with user-supplied data. While the taint analysis did not reveal critical or high severity issues, the presence of "flows with unsanitized paths" warrants caution, as this could potentially lead to vulnerabilities if combined with other insecure code patterns.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in SQL and output handling, the unprotected REST API routes and the use of "unserialize" represent tangible risks that require attention. The taint analysis, though not critical, highlights a need for careful review of data handling. Addressing these specific areas would significantly improve the plugin's overall security.
Key Concerns
- Unprotected REST API routes
- Use of unserialize function
- Flows with unsanitized paths
Changeloger – Changelog, Release Notes & User Feedback Security Vulnerabilities
Changeloger – Changelog, Release Notes & User Feedback Release Timeline
Changeloger – Changelog, Release Notes & User Feedback Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Changeloger – Changelog, Release Notes & User Feedback Attack Surface
REST API Routes 13
WordPress Hooks 33
Maintenance & Trust
Changeloger – Changelog, Release Notes & User Feedback Maintenance & Trust
Maintenance Signals
Community Trust
Changeloger – Changelog, Release Notes & User Feedback Alternatives
Product Roadmap
product-roadmap
Create public product roadmaps to share your vision, collect user feedback, and build products your customers actually want.
Unofficial – Frill.co SSO
unofficial-frill-sso
Unofficial Frill.co SSO plugin, enable SSO (Single-sign-on) login from WordPress to [Frill](https://frill.co/ "Frill.co")
Pufferbay
pufferbay
WordPress-native feature feedback, roadmap, voting, comments, changelog, and status notifications.
WP Roadmap – Product Feedback Board
wp-roadmap
WP Roadmap plugin is a perfect feedback and roadmap plugin tool that make adding roadmap and feedback easily to your WordPress website.
Simple Feature Requests Free – User Feedback Board
simple-feature-requests
Collect and manage user feedback using your existing WordPress website. Prioritize the product features important to you and your customers.
Changeloger – Changelog, Release Notes & User Feedback Developer Profile
9 plugins · 14K total installs
How We Detect Changeloger – Changelog, Release Notes & User Feedback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/changeloger/assets/css/frontend.css/wp-content/plugins/changeloger/assets/js/frontend.js/wp-content/plugins/changeloger/assets/css/changeloger.css/wp-content/plugins/changeloger/assets/js/changeloger.js/wp-content/plugins/changeloger/assets/js/frontend.js/wp-content/plugins/changeloger/assets/js/changeloger.jschangeloger/assets/css/frontend.css?ver=changeloger/assets/js/frontend.js?ver=changeloger/assets/css/changeloger.css?ver=changeloger/assets/js/changeloger.js?ver=HTML / DOM Fingerprints
wp-block-changeloger-changelog-block<!-- wp:block/changeloger<!-- wp:cha/changelogerchangelogerBlocks/wp-json/changeloger/v1/changelog