Dezo Tools Security & Risk Analysis

wordpress.org/plugins/dezo-tools

Dezo Tools is a plugin all in one to improve your wordpress.

10 active installs v0.2.0 PHP + WP 4.0+ Updated Sep 27, 2018
all-in-onetools
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dezo Tools Safe to Use in 2026?

Generally Safe

Score 85/100

Dezo Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The dezo-tools plugin v0.2.0 exhibits a generally strong security posture in its current static analysis. It boasts zero AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a remarkably small attack surface with no apparent unprotected entry points. The code signals also indicate good practices regarding SQL queries, as all are prepared, and there are no external HTTP requests. The absence of known CVEs in its vulnerability history further contributes to a positive security outlook.

However, there are notable areas for concern. The plugin has only 13 output operations, with a mere 15% being properly escaped, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the complete absence of nonce checks and capability checks, particularly in conjunction with the file operation, creates potential vulnerabilities. While taint analysis showed no issues, this might be due to the limited scope of the analysis or the lack of dynamic interaction being tested. The presence of file operations without apparent security checks is a significant risk.

In conclusion, while dezo-tools v0.2.0 has a clean vulnerability history and a small attack surface, the significant lack of output escaping and the presence of file operations without adequate security checks (nonce/capability) are critical weaknesses that warrant immediate attention. The plugin's current state suggests a potentially vulnerable product despite its clean past.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks
  • Missing capability checks
  • File operations without apparent checks
Vulnerabilities
None known

Dezo Tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Dezo Tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

15% escaped13 total outputs
Attack Surface

Dezo Tools Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionplugins_loadeddezo-tools.php:34
actioninitdezo-tools.php:35
actionadmin_menuincludes\admin\dezotools-admin.php:13
actionadmin_enqueue_scriptsincludes\admin\dezotools-admin.php:16
actionadmin_initincludes\admin\dezotools-admin.php:19
actionadmin_initincludes\admin\dezotools-admin.php:43
actionget_headerincludes\public\dezotools-minify.php:7
actionwp_headincludes\public\dezotools-public.php:13
actionwp_headincludes\public\dezotools-public.php:16
actionwp_footerincludes\public\dezotools-public.php:19
actionwp_enqueue_scriptsincludes\public\dezotools-public.php:22
actioninitincludes\public\dezotools-public.php:26
actioninitincludes\public\dezotools-public.php:30
filtertiny_mce_pluginsincludes\public\dezotools-public.php:94
filterwp_resource_hintsincludes\public\dezotools-public.php:95
Maintenance & Trust

Dezo Tools Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 27, 2018
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Dezo Tools Developer Profile

dezodev

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dezo Tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dezo-tools/assets/admin/css/dezo-tools.min.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Dezo Tools