Doohickey's Dev Tools Security & Risk Analysis

wordpress.org/plugins/doohickeys-dev-tools

Essential web development utilities right in your WordPress dashboard — CSS generators, color tools, code formatters, and more.

0 active installs v1.0.4 PHP 7.4+ WP 5.8+ Updated Unknown
code-toolscolor-pickercss-generatordeveloper-toolsweb-development
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Doohickey's Dev Tools Safe to Use in 2026?

Generally Safe

Score 100/100

Doohickey's Dev Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'doohickeys-dev-tools' plugin version 1.0.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, or file operations is a significant positive indicator. Furthermore, the complete lack of identified taint flows suggests that user-supplied data is not being mishandled in a way that could lead to code execution or data breaches. The plugin also shows no history of known vulnerabilities, which is a very reassuring sign of ongoing security diligence or a lack of prior exploitation.

While the plugin demonstrates good security practices, there are some areas that warrant attention. The most notable is the complete absence of any entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. This might indicate a very limited functionality or a plugin that relies on external triggers. However, it also means that the attack surface is effectively zero, which is excellent from a security perspective. The sole capability check suggests that some operations are protected by user roles. The inclusion of the Freemius v1.0 bundled library, while common, could be a potential concern if it is outdated and contains known vulnerabilities, though this is not indicated in the provided data. Overall, the plugin appears to be very secure as presented, with its main strength being its minimal and well-protected attack surface.

Key Concerns

  • Bundled Freemius v1.0 library
Vulnerabilities
None known

Doohickey's Dev Tools Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Doohickey's Dev Tools Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0
Attack Surface

Doohickey's Dev Tools Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initdoohickeys-dev-tools.php:27
actionplugins_loadeddoohickeys-dev-tools.php:91
actionadmin_menuincludes\class-admin.php:25
actionadmin_enqueue_scriptsincludes\class-admin.php:26
Maintenance & Trust

Doohickey's Dev Tools Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads215

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Doohickey's Dev Tools Developer Profile

mosaiclifecreative

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Doohickey's Dev Tools

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/doohickeys-dev-tools/build/index.js/wp-content/plugins/doohickeys-dev-tools/build/index.css
Script Paths
/wp-content/plugins/doohickeys-dev-tools/build/index.js
Version Parameters
doohickeys-dev-tools/build/index.js?ver=doohickeys-dev-tools/build/index.css?ver=

HTML / DOM Fingerprints

CSS Classes
dkdt-app
JS Globals
dkdtData
FAQ

Frequently Asked Questions about Doohickey's Dev Tools