
Core Rollback Security & Risk Analysis
wordpress.org/plugins/core-rollbackSeamless rollback of WordPress Core to latest release or any outdated, secure release using the Core Update API and core update methods.
Is Core Rollback Safe to Use in 2026?
Generally Safe
Score 100/100Core Rollback has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "core-rollback" plugin v1.4.1 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points suggests a minimal attack surface. Furthermore, the code signals are generally positive, with no dangerous functions, all SQL queries utilizing prepared statements, and a reasonable percentage of output being properly escaped. The presence of a nonce check is also a good security practice.
However, there are a couple of areas that warrant attention. The plugin makes two external HTTP requests, which can introduce vulnerabilities if not handled securely by the target endpoints or if the plugin doesn't implement appropriate validation and sanitization of the data sent or received. Additionally, the absence of capability checks on any potential entry points, although currently none are exposed, means that if new entry points were added without corresponding capability checks, they could be vulnerable to unauthorized access. The plugin also has no recorded vulnerability history, which is a positive indicator of past security development, but it doesn't guarantee future immunity.
In conclusion, the plugin appears to be well-secured with a limited attack surface and good coding practices in place for SQL and basic output handling. The primary concerns are the external HTTP requests and the lack of explicit capability checks, which could become a risk if the plugin's functionality expands or if the external services it communicates with are compromised. Overall, the plugin is in a good state, but vigilance is advised.
Key Concerns
- External HTTP requests
- Lack of capability checks
- Output escaping is not 100%
Core Rollback Security Vulnerabilities
Core Rollback Code Analysis
Output Escaping
Core Rollback Attack Surface
WordPress Hooks 7
Maintenance & Trust
Core Rollback Maintenance & Trust
Maintenance Signals
Community Trust
Core Rollback Alternatives
WP Downgrade | Specific Core Version
wp-downgrade
Automatically downgrad or update to any WordPress version you want directly from the backend.
Downgrade
downgrade
Downgrade WordPress
WP Rollback – Rollback Plugins and Themes
wp-rollback
Rollback (or forward) any WordPress.org plugin, theme, or block like a boss.
WP Core Update Cleaner
wp-core-update-cleaner
This plugin automatically removes some files in the root folder, like wp-config-sample.php, readme and license files, when WordPress is manually or au …
Version Hopper
version-hopper
Easily switch between versions of your WordPress plugins and themes directly from the admin dashboard.
Core Rollback Developer Profile
12 plugins · 43K total installs
How We Detect Core Rollback
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/core-rollback/core-rollback.php/wp-content/plugins/core-rollback/vendor/wp-core-rollback/wp-core-rollback.php/wp-content/plugins/core-rollback/core-rollback.phpcore-rollback/core-rollback.php?ver=1.4.1