
CleanCodeNZ Exclude Pages Plugin Security & Risk Analysis
wordpress.org/plugins/cleancode-exclude-pagesThis is a plugin to hide pages from navigation and/or search results using custom fields, parent and child pages are supported too
Is CleanCodeNZ Exclude Pages Plugin Safe to Use in 2026?
Generally Safe
Score 85/100CleanCodeNZ Exclude Pages Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cleancode-exclude-pages" plugin v2.0.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin has a zero-point attack surface, meaning it doesn't expose any AJAX handlers, REST API routes, shortcodes, or cron events, which are common entry points for vulnerabilities. Furthermore, it utilizes prepared statements for all SQL queries, preventing SQL injection risks, and has no file operations or external HTTP requests, further reducing its attack vectors. The complete absence of known CVEs and its clean vulnerability history also contribute to a positive security assessment, suggesting a well-maintained and secure codebase.
However, the analysis does highlight a significant concern: 100% of its output is not properly escaped. This means that any data outputted by the plugin, if it originates from user input or other external sources, could be vulnerable to Cross-Site Scripting (XSS) attacks. While the plugin has no direct entry points that are unauthenticated, if data is somehow introduced into the system and then outputted unescaped by this plugin, an attacker could potentially inject malicious scripts into the user's browser. The lack of nonce and capability checks, while not directly indicative of a vulnerability given the zero attack surface, could become a concern if future versions introduce any new entry points without adequate security measures. Overall, the plugin is well-protected against common server-side attacks, but the unescaped output presents a notable XSS risk that should be addressed.
Key Concerns
- Unescaped output
CleanCodeNZ Exclude Pages Plugin Security Vulnerabilities
CleanCodeNZ Exclude Pages Plugin Code Analysis
Output Escaping
CleanCodeNZ Exclude Pages Plugin Attack Surface
WordPress Hooks 4
Maintenance & Trust
CleanCodeNZ Exclude Pages Plugin Maintenance & Trust
Maintenance Signals
Community Trust
CleanCodeNZ Exclude Pages Plugin Alternatives
Exclude Pages
exclude-pages
This plugin adds a checkbox, “include this page in menus”, uncheck this to exclude pages from the page navigation that users see on your site.
Exclude Pages From Menu
exclude-pages-from-menu
The plugin provides option in the page edit screen to remove page from navigation menu in the front end of site.
Search box on Navigation Menu
search-box-on-navigation-menu
The plugin displays search form in the navigation bar which can be configured from the admin area.
TB Search in Menu
tb-search-in-menu
This plugin adds a search item in the nav menu of your choice
TreeMagic-Cypress
treemagic-cypress
TreeMagic Cypress is a new lightweight browser plugin for Word Press. By double clicking any word, or selecting a group of words on the page, It gives …
CleanCodeNZ Exclude Pages Plugin Developer Profile
1 plugin · 20 total installs
How We Detect CleanCodeNZ Exclude Pages Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrap