
Don Security Security & Risk Analysis
wordpress.org/plugins/don-securityThis plugin allows to set some security improvements to your WordPress site. Blocking attempts of scan from WPScan and other similar tools.
Is Don Security Safe to Use in 2026?
Generally Safe
Score 85/100Don Security has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'don-security' v1.0.2 exhibits a strong initial security posture based on the provided static analysis. It reports zero AJAX handlers, REST API routes, shortcodes, and cron events, indicating a minimal attack surface. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are positive indicators. The plugin also demonstrates no known vulnerabilities in its history.
However, a significant concern arises from the "Output escaping: 11 total outputs, 0% properly escaped" finding. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as any data rendered to the user without proper sanitization can be exploited. Additionally, the complete lack of nonce checks and capability checks on any potential entry points, while currently reported as zero, implies that if any were to be introduced or discovered, they would be unprotected. The absence of taint analysis flows might be due to the limited attack surface or the nature of the code, but the critical output escaping issue remains a prominent threat.
In conclusion, while the plugin has a clean vulnerability history and a seemingly small attack surface, the failure to properly escape output is a critical flaw that significantly elevates its risk profile. Developers should prioritize addressing this issue to mitigate XSS vulnerabilities. The lack of authentication checks is also a potential concern for future development.
Key Concerns
- Output escaping is not properly implemented
- No nonce checks implemented
- No capability checks implemented
Don Security Security Vulnerabilities
Don Security Code Analysis
Output Escaping
Don Security Attack Surface
WordPress Hooks 9
Maintenance & Trust
Don Security Maintenance & Trust
Maintenance Signals
Community Trust
Don Security Alternatives
Disable XML-RPC-API
disable-xml-rpc-api
A simple and lightweight plugin to disable XML-RPC API, X-Pingback and pingback-ping in WordPress 3.5+ for a faster and more secure website
Disable XML-RPC Pingback
disable-xml-rpc-pingback
Stops abuse of your site's XML-RPC by simply removing some methods used by attackers. While you can use the rest of XML-RPC methods.
Stop User Enumeration
stop-user-enumeration
Helps secure your site against hacking attacks through detecting User Enumeration
FluentAuth – The Ultimate Authorization & Security Plugin for WordPress
fluent-security
Enhance the Security and User Experience of Your Site with Login/Signup Security, Two-Factor Email Authentication, Social Logins and more...
Remove & Disable XML-RPC Pingback
remove-xmlrpc-pingback-ping
Prevent pingback, XML-RPC and denial of service DDOS attacks by disabling the XML-RPC pingback functionality.
Don Security Developer Profile
2 plugins · 40 total installs
How We Detect Don Security
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/don-security/admin/css/don-security-admin.css/wp-content/plugins/don-security/admin/js/don-security-admin.js/wp-content/plugins/don-security/admin/js/don-security-admin.jsdon-security-admin.css?ver=don-security-admin.js?ver=HTML / DOM Fingerprints
<!--
<!--