
1-Click Disable All Security & Risk Analysis
wordpress.org/plugins/first-graders-toolboxQuickly deactivate all active plugins with one click – ideal for troubleshooting plugin conflicts.
Is 1-Click Disable All Safe to Use in 2026?
Generally Safe
Score 100/1001-Click Disable All has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The static analysis of "first-graders-toolbox" v1.0.3 indicates a generally strong security posture. There are no identified dangerous functions, SQL queries use prepared statements exclusively, and all output is properly escaped. Furthermore, the absence of file operations and external HTTP requests minimizes common attack vectors. The presence of a nonce check is a positive sign of security awareness.
However, the plugin has a history of one known CVE, specifically a medium-severity Cross-Site Request Forgery (CSRF) vulnerability, which was last recorded on December 5, 2023. While this vulnerability is listed as patched, the fact that it existed in the first place warrants attention, especially since the current version v1.0.3 is not explicitly stated as being after this patch. The lack of capability checks on any entry points, though there are no entry points identified in this analysis, is a potential area for concern if functionality were to be added in the future without proper authorization checks.
In conclusion, the code itself appears to be well-written from a security perspective in this version, with no immediate critical or high risks detected within the static analysis. The primary concern stems from the past vulnerability history. While no vulnerabilities are currently unpatched, the presence of a CSRF issue suggests that careful auditing of any new features and continued vigilance are necessary. The absence of capability checks is a weakness that could become a significant risk if the plugin's functionality expands.
Key Concerns
- Past Medium Severity CVE (CSRF)
- No capability checks on entry points
1-Click Disable All Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
1 click disable all <= 1.0.1 - Cross-Site Request Forgery
1-Click Disable All Release Timeline
1-Click Disable All Code Analysis
Output Escaping
1-Click Disable All Attack Surface
WordPress Hooks 3
Maintenance & Trust
1-Click Disable All Maintenance & Trust
Maintenance Signals
Community Trust
1-Click Disable All Alternatives
CSGaku Site State Check
csgaku-site-state-check
Checks key WordPress site status items from the admin area without external API communication or automatic changes.
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Weborado Helper
weborado-helper
Essential tools for WordPress site administrators to monitor versions, enhance security, and improve performance.
Fuerte-WP
fuerte-wp
Protect your WordPress site from supply chain attacks, manage plugin updates, and control administrator access with intelligent automation.
AdminEase
adminease
Boosts your WordPress admin with tools for updates, security, performance, and user management - no coding required.
1-Click Disable All Developer Profile
13 plugins · 2K total installs
How We Detect 1-Click Disable All
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/first-graders-toolbox/script.js/wp-content/plugins/first-graders-toolbox/script.jsfirst-graders-toolbox/script.js?ver=HTML / DOM Fingerprints
atakanaufgt_script