
Code Revisions Security & Risk Analysis
wordpress.org/plugins/code-revisionsWordPress native revisions for the theme and plugin editors.
Is Code Revisions Safe to Use in 2026?
Generally Safe
Score 85/100Code Revisions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "code-revisions" v1.0 plugin presents a mixed security profile. On the positive side, it exhibits strong adherence to core WordPress security practices by not exposing any direct attack surface through AJAX, REST API, shortcodes, or cron events without proper authentication or permission checks. Furthermore, all SQL queries are properly prepared, and the plugin incorporates nonce and capability checks, demonstrating a good understanding of secure development principles. However, the static analysis reveals significant concerns, particularly in the taint analysis. Three total flows were analyzed, with all three exhibiting unsanitized paths, including one identified as critical severity. This indicates a high likelihood of a critical vulnerability that could be exploited if user-supplied input is not adequately sanitized before being processed, potentially leading to arbitrary code execution or other severe security breaches. The absence of any known vulnerabilities in its history is a positive indicator, suggesting that the developers may be proactive or that the identified taint issues haven't been publicly discovered or exploited yet. Despite a low attack surface and good use of prepared statements, the critical taint flow is a major red flag and necessitates immediate attention.
Key Concerns
- Critical severity taint flow with unsanitized path
- Unsanitized paths in all analyzed taint flows
- 50% of output not properly escaped
Code Revisions Security Vulnerabilities
Code Revisions Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Code Revisions Attack Surface
WordPress Hooks 12
Maintenance & Trust
Code Revisions Maintenance & Trust
Maintenance Signals
Community Trust
Code Revisions Alternatives
WPIDE – File Manager & Code Editor
wpide
WPIDE is a powerful file manager and code editor for WordPress with tabs, code completion, and full access to the entire wp-content folder.
WP Editor
wp-editor
WP Editor is a plugin for WordPress that replaces the default plugin and theme editors as well as the page/post editor.
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit
nexter-extension
Replace 50+ WordPress Plugins: Free Theme Builder, Code Snippets, Image Optimizer (WebP/AVIF), SMTP Email, Security Hardening, Performance & More
Simple Divi Shortcode
simple-divi-shortcode
Insert DIVI Library item inside module content or inside a php template by using a shortcode.
Weaver Xtreme Theme Support
weaverx-theme-support
A useful shortcode and widget collection for Weaver Xtreme
Code Revisions Developer Profile
4 plugins · 10K total installs
How We Detect Code Revisions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/code-revisions/css/editors.css/wp-content/plugins/code-revisions/js/editors.js/wp-content/plugins/code-revisions/js/editors.js/wp-content/plugins/code-revisions/css/editors.css?ver=/wp-content/plugins/code-revisions/js/editors.js?ver=HTML / DOM Fingerprints
window._code_revisions