
Delete Multiple Themes Security & Risk Analysis
wordpress.org/plugins/delete-multiple-themesEnable the administrator to delete multiple themes in one click.
Is Delete Multiple Themes Safe to Use in 2026?
Generally Safe
Score 85/100Delete Multiple Themes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "delete-multiple-themes" plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by having zero AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting its potential attack surface. Furthermore, all detected SQL queries are properly sanitized using prepared statements, and there are no recorded vulnerabilities or CVEs, suggesting a history of responsible development. However, a critical concern arises from the complete lack of output escaping. With 7 total outputs and 0% properly escaped, this opens the door to potential cross-site scripting (XSS) vulnerabilities. While taint analysis found no issues, this is likely due to the limited flows analyzed. The presence of a nonce check indicates some awareness of security, but the absence of capability checks on any entry points, combined with unescaped output, presents a significant risk.
Key Concerns
- Output escaping is completely missing
- No capability checks on entry points
Delete Multiple Themes Security Vulnerabilities
Delete Multiple Themes Code Analysis
Output Escaping
Delete Multiple Themes Attack Surface
WordPress Hooks 2
Maintenance & Trust
Delete Multiple Themes Maintenance & Trust
Maintenance Signals
Community Trust
Delete Multiple Themes Alternatives
No alternatives data available yet.
Delete Multiple Themes Developer Profile
6 plugins · 2K total installs
How We Detect Delete Multiple Themes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/delete-multiple-themes/templates/updates_form.phpHTML / DOM Fingerprints
the-listname="theme[]"value=''