DC Hide Publish Button Security & Risk Analysis

wordpress.org/plugins/dc-hide-publish-button

This plugin will come handy for author who often accidentally click publish button when what what they realy want is save only.

10 active installs v2.0.0 PHP + WP 4.7+ Updated Mar 25, 2017
page-editpagespostpost-editpublish-button
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DC Hide Publish Button Safe to Use in 2026?

Generally Safe

Score 85/100

DC Hide Publish Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin 'dc-hide-publish-button' v2.0.0 exhibits a strong security posture based on the provided static analysis. It demonstrates an absence of identified dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests. The plugin also correctly utilizes prepared statements for all SQL queries, indicating good data handling practices. Furthermore, the lack of known CVEs and a clean vulnerability history suggests a mature and well-maintained codebase.

However, a notable concern arises from the output escaping. With 38% of outputs properly escaped out of 8 total, there's a significant portion that is not, potentially leaving the plugin vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is reflected directly into the output without proper sanitization. While the attack surface is reported as zero, this percentage of unescaped output represents a tangible risk.

In conclusion, the plugin's strengths lie in its minimal attack surface and secure data handling for SQL. The primary weakness identified is the insufficient output escaping, which necessitates careful review of how dynamic content is displayed. Despite this, the absence of critical vulnerabilities and a clean history are positive indicators.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

DC Hide Publish Button Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DC Hide Publish Button Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
3 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped8 total outputs
Attack Surface

DC Hide Publish Button Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuclass.php:22
actionadmin_menuclass.php:23
actionadmin_headclass.php:24
actionadmin_initclass.php:47
actionplugins_loadeddc-hide-publish-button.php:25
Maintenance & Trust

DC Hide Publish Button Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMar 25, 2017
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

DC Hide Publish Button Developer Profile

Doni Susanto

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DC Hide Publish Button

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dc-hide-publish-button/dc-hide-publish-button.php
Version Parameters
dc-hide-publish-button/dc-hide-publish-button.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about DC Hide Publish Button