
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages Security & Risk Analysis
wordpress.org/plugins/freesoul-deactivate-pluginsLoad plugins only where you need them. No bloat, no conflicts, more speed. Deactivate plugins where they don't add anything useful.
Is Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages Safe to Use in 2026?
Generally Safe
Score 99/100Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "freesoul-deactivate-plugins" v2.5.0 plugin exhibits a mixed security posture. While it demonstrates strong adherence to output escaping (98%) and has a good number of capability checks, several areas raise significant concerns. The plugin possesses a substantial attack surface with 30 AJAX handlers, 19 of which lack authentication checks, presenting a direct pathway for unauthorized actions. The presence of the `unserialize` function, a known vector for deserialization vulnerabilities, is also a notable risk. Furthermore, the taint analysis reveals a high number of unsanitized paths (17 out of 27 flows) and a high-severity flow, indicating potential for attackers to manipulate plugin behavior or access unauthorized data.
The plugin's vulnerability history, with two previously disclosed CVEs (one medium and one low severity), including common types like CSRF and information exposure, suggests a past tendency towards vulnerabilities that allow unauthorized actions or data leaks. Although there are currently no unpatched vulnerabilities, the historical pattern combined with the static analysis findings warrants caution. The plugin's strengths lie in its proper output escaping and a decent number of capability checks, but these are overshadowed by the numerous unprotected AJAX endpoints and the identified taint flow issues.
In conclusion, while the plugin has some good security practices, the large number of unprotected AJAX endpoints, the use of `unserialize`, and the concerning taint analysis results present significant risks. The historical vulnerability patterns further reinforce the need for careful monitoring and prompt updates. Users should be aware of the potential for unauthorized plugin deactivation or manipulation.
Key Concerns
- 19 unprotected AJAX handlers
- Use of unserialize function
- 1 High severity taint flow
- 17 unsanitized paths in taint flows
- Medium severity CVE history
- Low severity CVE history
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Freesoul Deactivate Plugins <= 2.1.3 - Cross-Site Request Forgery via eos_dp_pro_delete_transient
Freesoul Deactivate Plugins <= 1.9.4.0 - Information Disclosure
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages Release Timeline
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages Attack Surface
AJAX Handlers 30
WordPress Hooks 221
Maintenance & Trust
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages Maintenance & Trust
Maintenance Signals
Community Trust
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages Alternatives
Editor Cleanup For Elementor: clean up and solve plugin conflicts with the Elementor editor
editor-cleanup-for-elementor
FDP add-on to clean up the editor of Elementor. The Elementor editor will be faster and without conflicts with other plugins.
Editor Cleanup For Oxygen: FDP add-on to cleanup the Oxygen editor
editor-cleanup-for-oxygen
FDP add-on to cleanup Oxygen in the backend. Your Oxygen backend will be faster and without conflicts with other plugins.
Editor Cleanup For Avada: FDP add-on to cleanup the Avada frontend editor
editor-cleanup-for-avada
FDP add-on to cleanup the frontend editor of Avada. Your Avada frontend editor will be faster and without conflicts with other plugins.
Unplug
unplug
Cut the plugin bloat. See which plugins are actually being used on your sites and which ones are just plugin bloat.
Delete Duplicate Posts
delete-duplicate-posts
Get rid of duplicate posts and pages (any post type) on your blog with manual or automatic modes.
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages Developer Profile
58 plugins · 26K total installs
How We Detect Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/freesoul-deactivate-plugins/admin/css/eos-dp-admin.css/wp-content/plugins/freesoul-deactivate-plugins/admin/css/eos-dp-admin-new.css/wp-content/plugins/freesoul-deactivate-plugins/admin/css/bootstrap.min.css/wp-content/plugins/freesoul-deactivate-plugins/admin/js/eos-dp-admin.js/wp-content/plugins/freesoul-deactivate-plugins/admin/js/eos-dp-admin-new.js/wp-content/plugins/freesoul-deactivate-plugins/admin/js/eos-dp-admin.js/wp-content/plugins/freesoul-deactivate-plugins/admin/js/eos-dp-admin-new.jsfreesoul-deactivate-plugins/admin/css/eos-dp-admin.css?ver=freesoul-deactivate-plugins/admin/css/eos-dp-admin-new.css?ver=freesoul-deactivate-plugins/admin/css/bootstrap.min.css?ver=freesoul-deactivate-plugins/admin/js/eos-dp-admin.js?ver=freesoul-deactivate-plugins/admin/js/eos-dp-admin-new.js?ver=HTML / DOM Fingerprints
eos-dp-admin-wrapeos-dp-admin-contenteos-dp-admin-roweos-dp-admin-col<!-- It fires on Ajax requests. --><!-- Saves activation/deactivation settings for each post. --><!-- Saves activation/deactivation settings for each archive. --><!-- Saves activation/deactivation settings for each post type. -->+1 moredata-page_slugdata-eos_dp_pt_settsdata-eos_dp_pt_setts_iddata-eos_dp_settingsdata-eos_dp_urlsdata-eos_dp_need_custom_url+7 moreeos_dp_ajax_object/wp-json/fdp-api/v1/get-plugins