
Discourage Search Engines by URL Security & Risk Analysis
wordpress.org/plugins/discourage-search-engines-by-urlAllows you to discourage search engines by url to prevent you from forgetting to turn the setting off when transfering databases between development a …
Is Discourage Search Engines by URL Safe to Use in 2026?
Generally Safe
Score 85/100Discourage Search Engines by URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "discourage-search-engines-by-url" plugin v0.2.1 exhibits a generally positive security posture based on the provided static analysis. The plugin has no known CVEs, a clean vulnerability history, and a notably absent attack surface with zero entry points (AJAX, REST API, shortcodes, cron events). The code also avoids dangerous functions, file operations, and external HTTP requests. Importantly, all SQL queries utilize prepared statements, which is a strong defense against SQL injection. However, a significant concern arises from the output escaping. With 5 total outputs analyzed, only 20% (1 output) are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as unsanitized data could be injected into the frontend and executed by users' browsers. The lack of nonce and capability checks, while not directly exploitable due to the zero attack surface, represents a missed opportunity for layered security that could become a liability if the attack surface expands in future versions. The absence of taint analysis flows is also noteworthy, suggesting either a lack of complex data handling or that the analysis tool did not identify any concerning data flows within the plugin's current scope. Overall, while the plugin demonstrates good practices in core areas like SQL and attack surface management, the poor output escaping is a critical weakness that needs immediate attention.
Key Concerns
- Poor output escaping (20% escaped)
- No nonce checks
- No capability checks
Discourage Search Engines by URL Security Vulnerabilities
Discourage Search Engines by URL Release Timeline
Discourage Search Engines by URL Code Analysis
Output Escaping
Discourage Search Engines by URL Attack Surface
WordPress Hooks 3
Maintenance & Trust
Discourage Search Engines by URL Maintenance & Trust
Maintenance Signals
Community Trust
Discourage Search Engines by URL Alternatives
Search engines blocked warning
search-engines-blocked-warning
Shows a warning in the WordPress administration header when the option "Search Engine Visibility: Discourage search engines from indexing this si …
Discourage Search Engines – Dashboard notification
discourage-search-engines-dashboard-notification
Show a dashboard notification to remind you that 'Discourage Search Engines' is still enabled in the settings.
Check Search Engine Visibility on Migration
check-search-engine-visibility-on-migration
Checks if a site it's inivisible to search engines after a migration. If so, then the plugin warns you to review this setting.
Better Search Replace
better-search-replace
A simple plugin to update URLs or other text in a database.
Go Live Update Urls
go-live-update-urls
Change the domain on your site with one click.
Discourage Search Engines by URL Developer Profile
2 plugins · 280 total installs
How We Detect Discourage Search Engines by URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
dashicons-visibilitydashicons-beforedashicons-dashboardid="dseburl_url"name="dseburl_url"id="dseburl_hide_icon"name="dseburl_hide_icon"id="dseburl"id="dseburl-group"+3 more