
Content Visibility Security & Risk Analysis
wordpress.org/plugins/content-visibilityDecide when, where, and to whom your blocks are visible.
Is Content Visibility Safe to Use in 2026?
Generally Safe
Score 85/100Content Visibility has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "content-visibility" plugin v0.2.9 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code demonstrates good practices by exclusively using prepared statements for SQL queries, performing proper output escaping on all identified outputs, and avoiding dangerous functions and file operations. The plugin also correctly implements capability checks, indicating an awareness of access control mechanisms. The lack of any recorded vulnerabilities, past or present, further reinforces this positive assessment.
However, the most significant concern arises from the complete absence of nonce checks. While the attack surface is currently minimal, any future introduction of functionality that could be exploited by Cross-Site Request Forgery (CSRF) attacks would be unprotected. The taint analysis showing zero flows, while positive, might be a reflection of the limited attack surface rather than an exhaustive analysis of all potential data flows within more complex plugins. Therefore, while the current version appears very secure, the lack of nonce checks represents a potential weakness that should be addressed proactively if the plugin's functionality expands.
Key Concerns
- Missing nonce checks
Content Visibility Security Vulnerabilities
Content Visibility Release Timeline
Content Visibility Code Analysis
Output Escaping
Content Visibility Attack Surface
WordPress Hooks 12
Maintenance & Trust
Content Visibility Maintenance & Trust
Maintenance Signals
Community Trust
Content Visibility Alternatives
Responsive Visibility for Blocks Editor (Hide/Show Blocks for Devices)
responsive-visibility
🌟 Enhance Your WordPress Site with Responsive Visibility for Gutenberg Blocks
Content Visibility Date and Time
content-visibility-date-and-time
A date and time add-on for Content Visibility.
Content Visibility Geolocation
content-visibility-geolocation
A geolocation add-on for Content Visibility.
Content Visibility Specific Users
content-visibility-specific-users
A Specific Users add-on for Content Visibility.
Content Visibility RSS Feed
content-visibility-rss-feed
As RSS Feed add-on for Content Visibility.
Content Visibility Developer Profile
6 plugins · 140 total installs
How We Detect Content Visibility
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/content-visibility/includes/editor/editor.css/wp-content/plugins/content-visibility/includes/public/content-visibility-public.css/wp-content/plugins/content-visibility/includes/editor/editor.js/wp-content/plugins/content-visibility/includes/public/public-rules.js/wp-content/plugins/content-visibility/includes/editor/editor.js/wp-content/plugins/content-visibility/includes/public/public-rules.jscontent-visibility-publiccontent-visibility-editorHTML / DOM Fingerprints
content-visibility-editor-rules-wrappercontent-visibility-editor-rule-controls<!-- Content Visibility --><!-- Content Visibility -->
<div class="content-visibility-editor-rules-wrapper">data-content-visibility-rule-iddata-content-visibility-rule-typewindow.ContentVisibility