
Clean My Archives Security & Risk Analysis
wordpress.org/plugins/clean-my-archivesAn easy-to-use shortcode for displaying post archives on your site.
Is Clean My Archives Safe to Use in 2026?
Generally Safe
Score 85/100Clean My Archives has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "clean-my-archives" v1.2.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL injection risks (all queries use prepared statements), file operations, external HTTP requests, and all outputs being properly escaped are significant strengths. The plugin also has a clean vulnerability history, with no known CVEs, indicating a history of secure development or prompt patching.
However, there are a couple of areas that warrant attention. The presence of a shortcode without any explicit capability checks is a potential concern. While the attack surface is small, an unprotected shortcode could be an entry point for actions that might not be intended for all users, depending on its functionality. The static analysis also noted zero nonce checks, which is a standard security measure to prevent Cross-Site Request Forgery (CSRF) attacks, particularly on any actions initiated via the shortcode.
In conclusion, the plugin is well-developed from a secure coding practices perspective, especially concerning data handling and output sanitization. The lack of historical vulnerabilities is a positive sign. The primary weaknesses lie in the potential for CSRF due to missing nonce checks and the lack of explicit capability checks on the shortcode, although the overall impact is mitigated by the limited attack surface and the absence of other common vulnerabilities.
Key Concerns
- Shortcode without capability checks
- Missing nonce checks
Clean My Archives Security Vulnerabilities
Clean My Archives Code Analysis
Output Escaping
Clean My Archives Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Clean My Archives Maintenance & Trust
Maintenance Signals
Community Trust
Clean My Archives Alternatives
Extra Shortcodes
extra-shortcodes
[extra_archives], [extra_taxonomies], [bloginfo show="name"], [date format="l jS \of F Y"], [date_i18n], [time]
Child Pages Card
child-pages-card
Displays child page archives in card form.
CC-List-Posts
cc-list-posts
This plugin adds similar to wp_list_pages, missing function and shortcode wp_list_posts with pagination support.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Clean My Archives Developer Profile
33 plugins · 34K total installs
How We Detect Clean My Archives
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
clean-my-archivesmonth-yeardayday-duplicatecomments-number[clean-my-archives]<div class="clean-my-archives">