Disable Updates by CV Security & Risk Analysis

wordpress.org/plugins/disable-updates-by-cv

Plugins, themes and the core update can be disabled from the setting page.

0 active installs v1.0.1 PHP 5.6+ WP 3.0.1+ Updated Aug 29, 2024
auto-updatedisable-updatepluginsthemes
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Disable Updates by CV Safe to Use in 2026?

Generally Safe

Score 92/100

Disable Updates by CV has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'disable-updates-by-cv' plugin version 1.0.1 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals a complete absence of dangerous functions, SQL queries, file operations, and external HTTP requests, indicating a very clean codebase. Crucially, all detected SQL queries utilize prepared statements, and all output is properly escaped, mitigating common web vulnerabilities. The presence of a nonce check and a capability check further strengthens its security, ensuring that actions are authorized and protected against replay attacks. The plugin also boasts a clean vulnerability history with zero known CVEs, suggesting a well-maintained and secure development practice.

While the plugin demonstrates excellent adherence to security best practices in its code, the most significant observation is the extremely limited attack surface. With zero AJAX handlers, REST API routes, shortcodes, and cron events, there are no apparent entry points for attackers to exploit within the plugin's functionality. This is a significant strength. The taint analysis also shows no critical or high severity flows, reinforcing the confidence in its security. Overall, this plugin appears to be a highly secure and well-developed option for its intended purpose, with no identified weaknesses or vulnerabilities in the analyzed data.

Vulnerabilities
None known

Disable Updates by CV Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Disable Updates by CV Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Disable Updates by CV Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
87 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped87 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
dufw_admin_menu_save_callback (admin/class-disable-updates-for-wordpress-admin.php:241)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Disable Updates by CV Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
filterpre_option_update_coreadmin/class-disable-updates-for-wordpress-admin.php:104
filterauto_update_translationadmin/class-disable-updates-for-wordpress-admin.php:123
filterautomatic_updater_disabledadmin/class-disable-updates-for-wordpress-admin.php:124
filterallow_minor_auto_core_updatesadmin/class-disable-updates-for-wordpress-admin.php:125
filterallow_major_auto_core_updatesadmin/class-disable-updates-for-wordpress-admin.php:126
filterallow_dev_auto_core_updatesadmin/class-disable-updates-for-wordpress-admin.php:127
filterauto_update_coreadmin/class-disable-updates-for-wordpress-admin.php:128
filterwp_auto_update_coreadmin/class-disable-updates-for-wordpress-admin.php:129
filterauto_core_update_send_emailadmin/class-disable-updates-for-wordpress-admin.php:130
filtersend_core_update_notification_emailadmin/class-disable-updates-for-wordpress-admin.php:131
filterauto_update_pluginadmin/class-disable-updates-for-wordpress-admin.php:132
filterauto_update_themeadmin/class-disable-updates-for-wordpress-admin.php:133
filterautomatic_updates_send_debug_emailadmin/class-disable-updates-for-wordpress-admin.php:134
filterautomatic_updates_is_vcs_checkoutadmin/class-disable-updates-for-wordpress-admin.php:135
filterautomatic_updates_send_debug_email admin/class-disable-updates-for-wordpress-admin.php:138
actionplugins_loadedincludes/class-disable-updates-for-wordpress.php:142
actionadmin_enqueue_scriptsincludes/class-disable-updates-for-wordpress.php:157
actionadmin_enqueue_scriptsincludes/class-disable-updates-for-wordpress.php:158
actionadmin_menuincludes/class-disable-updates-for-wordpress.php:161
actioninitincludes/class-disable-updates-for-wordpress.php:163
actionadmin_noticesincludes/class-disable-updates-for-wordpress.php:165
filterremovable_query_argsincludes/class-disable-updates-for-wordpress.php:167
filtersite_transient_update_pluginsincludes/class-disable-updates-for-wordpress.php:169
filtersite_transient_update_themesincludes/class-disable-updates-for-wordpress.php:171
filteradmin_initincludes/class-disable-updates-for-wordpress.php:173
actionwp_enqueue_scriptsincludes/class-disable-updates-for-wordpress.php:187
actionwp_enqueue_scriptsincludes/class-disable-updates-for-wordpress.php:188
Maintenance & Trust

Disable Updates by CV Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 29, 2024
PHP min version5.6
Downloads816

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Disable Updates by CV Developer Profile

Chetan Vaghela

12 plugins · 590 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable Updates by CV

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/disable-updates-by-cv/css/disable-updates-for-wordpress-admin.css
Script Paths
/wp-content/plugins/disable-updates-by-cv/js/disable-updates-for-wordpress-admin.js
Version Parameters
disable-updates-for-wordpress-admin.css?ver=disable-updates-for-wordpress-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable Updates by CV