
Changelogger Security & Risk Analysis
wordpress.org/plugins/changeloggerChangelogger shows the latest changelog right on the plugin listing page, whenever there's a plugin ready to be updated.
Is Changelogger Safe to Use in 2026?
Generally Safe
Score 100/100Changelogger has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "changelogger" v1.3.4 plugin presents a mixed security posture. On the positive side, it exhibits a clean vulnerability history with no recorded CVEs, indicating a potentially well-maintained codebase. The absence of dangerous functions, file operations, external HTTP requests, and the sole use of prepared statements for SQL queries are strong security indicators. However, a significant concern arises from the presence of an unprotected AJAX handler, which represents the entire attack surface of the plugin. This lack of authentication on a direct entry point exposes the plugin to potential unauthorized actions if the handler's functionality can be exploited. While taint analysis shows no critical or high-severity flows, the limited scope of analysis (0 flows analyzed) might not cover all potential risks.
The plugin's strengths lie in its diligent use of prepared statements and its clean CVE record. Conversely, the unprotected AJAX handler is a clear weakness. The limited output escaping (40% properly escaped) also presents a potential risk for cross-site scripting (XSS) vulnerabilities, though the absence of taint flows involving unsanitized paths provides some mitigation. Overall, the plugin has a reasonable foundation but requires immediate attention to secure its AJAX endpoint to prevent potential exploits.
Key Concerns
- Unprotected AJAX handler
- Low output escaping percentage
- No nonce checks on AJAX handlers
Changelogger Security Vulnerabilities
Changelogger Code Analysis
Output Escaping
Changelogger Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Changelogger Maintenance & Trust
Maintenance Signals
Community Trust
Changelogger Alternatives
Version Control for jQuery
version-control-for-jquery
Version Control for jQuery is one of the easiest ways to control the version of jQuery used on your website.
Better Plugin Compatibility Control
better-plugin-compatibility-control
Adds version compatibility info to the plugins page to inform the admin at a glance if a plugin is compatible with the current WP and PHP version.
WP Document Revisions
wp-document-revisions
A document management and version control plugin for WordPress that allows teams of any size to collaboratively edit files and manage their workflow.
WP Revision Master
wp-revision-master
Powerful and best post revision control, compare, restore!
WP Theme Changelogs
wp-theme-changelogs
Adding changelogs for themes hosted on wordpress.org by parsing their readme.txt
Changelogger Developer Profile
7 plugins · 79K total installs
How We Detect Changelogger
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/changelogger/js/admin_scripts.js/wp-content/plugins/changelogger/css/style.css/wp-content/plugins/changelogger/js/admin_scripts.jschangelogger/js/admin_scripts.js?ver=changelogger/css/style.css?ver=HTML / DOM Fingerprints
clos-plugin-updateclos-messageclos-arrwid="clos-message-onclick="clos_ajax_load_changelog(clos_ajax_load_changelog