
Disable Unused WP Features Security & Risk Analysis
wordpress.org/plugins/disable-unused-wp-featuresClean up WordPress by disabling rarely used features like XML-RPC, Emojis, RSS, Gutenberg, REST API, Heartbeat, and Dashicon all in one place.
Is Disable Unused WP Features Safe to Use in 2026?
Generally Safe
Score 100/100Disable Unused WP Features has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "disable-unused-wp-features" plugin v1.0.1 exhibits a very strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, or unescaped output signals robust development practices. Furthermore, the plugin has no identified external attack surface through AJAX, REST API, shortcodes, or cron events, and importantly, no taint analysis revealed any unsanitized data flows. The plugin's vulnerability history is also clean, with zero recorded CVEs, indicating a history of secure development or effective vulnerability management. However, a notable concern is the complete absence of nonce and capability checks across all code signals. While the current lack of an exposed attack surface mitigates immediate risk, future development that introduces entry points without these crucial security measures would create significant vulnerabilities. The plugin's current strength lies in its minimal attack surface and clean code, but the lack of essential WordPress security features like nonces and capability checks represents a potential weakness that could be exploited if the plugin evolves.
Key Concerns
- Missing nonce checks
- Missing capability checks
Disable Unused WP Features Security Vulnerabilities
Disable Unused WP Features Code Analysis
Output Escaping
Disable Unused WP Features Attack Surface
WordPress Hooks 15
Maintenance & Trust
Disable Unused WP Features Maintenance & Trust
Maintenance Signals
Community Trust
Disable Unused WP Features Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Classic Editor and Classic Widgets
classic-editor-and-classic-widgets
Disables Gutenberg editor totally everywhere and enables Classic Editor and Classic Widgets.
Enable Classic Editor & Widgets
enable-classic-editor
A simple & lightweight plugin to enable the classic editor on WordPress with advanced configuration options.
Disable Gutenberg
auto-disable-editor
Auto Disable gutenberg plugin will help you to disable gutenberg block editor
Remove Gutenberg
restore-classic-editor
Remove Gutenberg Editor and get back to old version of editor. This provides Original Classic Editor and more.
Disable Unused WP Features Developer Profile
4 plugins · 10 total installs
How We Detect Disable Unused WP Features
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/disable-unused-wp-features/assets/css/admin-style.min.css/wp-content/plugins/disable-unused-wp-features/assets/js/duwf-admin.min.js/wp-content/plugins/disable-unused-wp-features/assets/js/duwf-admin.min.jsdisable-unused-wp-features/assets/css/admin-style.min.css?ver=disable-unused-wp-features/assets/js/duwf-admin.min.js?ver=