1 click disable all Security & Risk Analysis

wordpress.org/plugins/first-graders-toolbox

Disable all plugins with one click

0 active installs v1.0.3 PHP 5.6+ WP 5.0+ Updated Apr 9, 2025
accessadmindisableremotetool
100
A · Safe
CVEs total1
Unpatched0
Last CVEDec 5, 2023
Safety Verdict

Is 1 click disable all Safe to Use in 2026?

Generally Safe

Score 100/100

1 click disable all has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 5, 2023Updated 11mo ago
Risk Assessment

The static analysis of "first-graders-toolbox" v1.0.3 indicates a generally strong security posture. There are no identified dangerous functions, SQL queries use prepared statements exclusively, and all output is properly escaped. Furthermore, the absence of file operations and external HTTP requests minimizes common attack vectors. The presence of a nonce check is a positive sign of security awareness.

However, the plugin has a history of one known CVE, specifically a medium-severity Cross-Site Request Forgery (CSRF) vulnerability, which was last recorded on December 5, 2023. While this vulnerability is listed as patched, the fact that it existed in the first place warrants attention, especially since the current version v1.0.3 is not explicitly stated as being after this patch. The lack of capability checks on any entry points, though there are no entry points identified in this analysis, is a potential area for concern if functionality were to be added in the future without proper authorization checks.

In conclusion, the code itself appears to be well-written from a security perspective in this version, with no immediate critical or high risks detected within the static analysis. The primary concern stems from the past vulnerability history. While no vulnerabilities are currently unpatched, the presence of a CSRF issue suggests that careful auditing of any new features and continued vigilance are necessary. The absence of capability checks is a weakness that could become a significant risk if the plugin's functionality expands.

Key Concerns

  • Past Medium Severity CVE (CSRF)
  • No capability checks on entry points
Vulnerabilities
1

1 click disable all Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-21749medium · 4.3Cross-Site Request Forgery (CSRF)

1 click disable all <= 1.0.1 - Cross-Site Request Forgery

Dec 5, 2023 Patched in 1.0.2 (97d)
Code Analysis
Analyzed Mar 17, 2026

1 click disable all Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

1 click disable all Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menufirst-graders-toolbox.php:23
actionadmin_enqueue_scriptsfirst-graders-toolbox.php:24
filterplugin_row_metafirst-graders-toolbox.php:25
Maintenance & Trust

1 click disable all Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 9, 2025
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

1 click disable all Developer Profile

Atakan Au

10 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
27 days
View full developer profile
Detection Fingerprints

How We Detect 1 click disable all

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/first-graders-toolbox/script.js
Script Paths
/wp-content/plugins/first-graders-toolbox/script.js
Version Parameters
first-graders-toolbox/script.js?ver=

HTML / DOM Fingerprints

JS Globals
atakanaufgt_script
FAQ

Frequently Asked Questions about 1 click disable all