
Extension Profiles Security & Risk Analysis
wordpress.org/plugins/extension-profilesCreate named profiles to quickly switch between different sets of active plugins per user session.
Is Extension Profiles Safe to Use in 2026?
Generally Safe
Score 100/100Extension Profiles has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "extension-profiles" plugin v1.0.0 demonstrates a generally good security posture with several strengths. Notably, it shows no history of known vulnerabilities (CVEs) and uses prepared statements for all SQL queries, indicating a strong defense against SQL injection. The plugin also has a high percentage of properly escaped outputs and incorporates nonce checks and capability checks, which are essential for secure WordPress development. However, there are significant concerns regarding its attack surface. The presence of two AJAX handlers without any authentication checks presents a clear risk. This means that any unauthenticated user can trigger these AJAX actions, potentially leading to unintended consequences or exploitation if the functionality is sensitive. While no critical taint flows or dangerous functions were detected in the static analysis, this lack of authentication on entry points is a substantial weakness that requires immediate attention.
Key Concerns
- AJAX handlers without auth checks
Extension Profiles Security Vulnerabilities
Extension Profiles Code Analysis
Output Escaping
Data Flow Analysis
Extension Profiles Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Extension Profiles Maintenance & Trust
Maintenance Signals
Community Trust
Extension Profiles Alternatives
Admin Bar Tools
sf-adminbar-tools
Adds some small development tools to the admin bar.
Eli's PHP Compatibility Scanner
eli-php-compatibility-scanner
A comprehensive WordPress plugin that scans your plugins and themes for PHP version compatibility issues using the PHPCompatibility ruleset.
User Role Switcher
wp-user-role-switcher
Instant switching between user roles in WordPress.
Test Email Redirector
test-email-redirector
Redirects all outgoing WordPress emails to a specified test address for development and testing purposes.
Back To The Theme
back-to-the-theme
See a page with different themes all at once, just like that!
Extension Profiles Developer Profile
4 plugins · 470 total installs
How We Detect Extension Profiles
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extension-profiles/assets/css/extension-profiles.css/wp-content/plugins/extension-profiles/assets/js/extension-profiles.js/wp-content/plugins/extension-profiles/assets/js/extension-profiles.jsextension-profiles/assets/css/extension-profiles.css?ver=extension-profiles/assets/js/extension-profiles.js?ver=HTML / DOM Fingerprints
extension-profiles-admin-noticedata-extension-profiles-plugin-fileExtensionProfilesAdmin