Disable jQuery Migrate Security & Risk Analysis

wordpress.org/plugins/disable-jquery-migrate

A simple plugin to disable loading of jquery-migrate on the frontend due to a XSS vulerability of jQuery Migrate 1.2.1.

100 active installs v1.0 PHP + WP 4.3.1+ Updated Oct 7, 2015
jqueryjquery-migratesecurity
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Disable jQuery Migrate Safe to Use in 2026?

Generally Safe

Score 85/100

Disable jQuery Migrate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'disable-jquery-migrate' plugin v1.0 exhibits a strong security posture based on the provided static analysis. The absence of identified dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries indicate good coding practices. Crucially, there are no identified taint flows, meaning there are no apparent pathways for unsanitized data to lead to vulnerabilities. The plugin also scores perfectly on output escaping, further reinforcing its secure development.

The vulnerability history is also exceptionally clean, with no recorded CVEs of any severity. This suggests a history of responsible development and maintenance, or perhaps a lack of past scrutiny due to its apparent simplicity. The complete lack of any identified attack surface entry points (AJAX, REST API, shortcodes, cron events) is a significant strength, as it means there are no direct avenues for external interaction that could be exploited.

While the plugin's current version appears to be highly secure, its complete lack of any entry points for analysis (0 AJAX handlers, 0 REST API routes, 0 shortcodes, 0 cron events) and 0 taint flows analyzed, while positive, also means there's limited data to assess potential issues if its functionality were to expand. The absence of capability and nonce checks, though not a direct vulnerability in this context due to the lack of an attack surface, could become a concern if the plugin were to evolve and introduce new functionalities with user interaction.

Vulnerabilities
None known

Disable jQuery Migrate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Disable jQuery Migrate Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Disable jQuery Migrate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable jQuery Migrate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwp_default_scriptsdisable-jquery-migrate.php:15
Maintenance & Trust

Disable jQuery Migrate Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedOct 7, 2015
PHP min version
Downloads13K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Disable jQuery Migrate Developer Profile

ivanblagdan

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable jQuery Migrate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable jQuery Migrate