
Disallow PNG Security & Risk Analysis
wordpress.org/plugins/disallow-pngDisallows PNG files. Usefor for multi-user environments with restrictive file settings and performance oriented sites.
Is Disallow PNG Safe to Use in 2026?
Generally Safe
Score 85/100Disallow PNG has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the 'disallow-png' v1.0 plugin exhibits a strong security posture. The absence of any identified dangerous functions, SQL injection vulnerabilities, file operations, external HTTP requests, or issues with output escaping suggests that the code has been written with security best practices in mind. The lack of any recorded CVEs and the thoroughness of the static analysis (0 flows, 0 unsanitized paths) further reinforce this assessment.
While the plugin's functionality appears minimal, leading to a zero attack surface and zero entry points without authentication checks, it's important to note that this does not inherently mean it is immune to all potential future vulnerabilities. The complete absence of capability checks and nonce checks is a consequence of the zero attack surface, and thus not a direct concern for this version. However, if the plugin were to be extended in the future to include new entry points, these would need to be carefully secured.
In conclusion, the 'disallow-png' v1.0 plugin appears to be secure based on the provided data. Its minimal attack surface and lack of known vulnerabilities are significant strengths. The primary "weakness" is the potential for future security concerns should the plugin's functionality expand without adhering to security principles, but this is speculative and not a current issue.
Disallow PNG Security Vulnerabilities
Disallow PNG Code Analysis
Disallow PNG Attack Surface
WordPress Hooks 1
Maintenance & Trust
Disallow PNG Maintenance & Trust
Maintenance Signals
Community Trust
Disallow PNG Alternatives
WEN Featured Image
wen-featured-image
Add featured image column in listings. Add/change/remove featured image directly from the listing page
wp_upload_rename
wp-upload-rename
Change upload filename to random characters / random numbers / date / other by yourself.
Add From Server
add-from-server
Add From Server is designed to help ease the pain of bad web hosts, allowing you to upload files via FTP or SSH and later import them into WordPress.
Clean Image Filenames
clean-image-filenames
This plugin automatically converts language accent characters to non-accent characters in filenames when uploading to the media library.
Disable Media Sizes
disable-media-sizes
Provides options to disable the extra images generated by WordPress.
Disallow PNG Developer Profile
9 plugins · 630 total installs
How We Detect Disallow PNG
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.