Discourage Search Engines Notifier Security & Risk Analysis

wordpress.org/plugins/discourage-search-engines-notifier

Shows an admin bar icon indicating your site's search engine visibility status.

200 active installs v2.6.0 PHP + WP 3.5+ Updated Nov 10, 2025
developerdevelopmentnotifierseotool
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Discourage Search Engines Notifier Safe to Use in 2026?

Generally Safe

Score 100/100

Discourage Search Engines Notifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "discourage-search-engines-notifier" plugin v2.6.0 presents a generally positive security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests, which are all strong indicators of secure coding practices. The fact that all SQL queries utilize prepared statements is also a major strength.

However, a significant concern arises from the output escaping. With 1 total output and 0% properly escaped, any data displayed to users or browsers could potentially be vulnerable to cross-site scripting (XSS) attacks. The lack of any identified taint flows or vulnerabilities in its history is reassuring, suggesting the plugin hasn't had publicly known security flaws. Despite this positive history, the unescaped output is a concrete, actionable risk that needs immediate attention.

In conclusion, while the plugin benefits from a minimal attack surface and adherence to secure coding for database interactions, the critical flaw in output escaping poses a significant risk. The absence of historical vulnerabilities is a good sign, but it does not negate the present danger of unescaped output. Addressing the output escaping is paramount to improving its security.

Key Concerns

  • Unescaped output
Vulnerabilities
None known

Discourage Search Engines Notifier Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Discourage Search Engines Notifier Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Discourage Search Engines Notifier Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_bar_menudiscourage-search-engines-notifier.php:47
Maintenance & Trust

Discourage Search Engines Notifier Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 10, 2025
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings4
Active installs200
Developer Profile

Discourage Search Engines Notifier Developer Profile

MΛCHINΣ CØDΣ

2 plugins · 220 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Discourage Search Engines Notifier

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
ab-icon
FAQ

Frequently Asked Questions about Discourage Search Engines Notifier