
General Options Security & Risk Analysis
wordpress.org/plugins/general-optionsThis plugin allows the end user to upload a Header logo , Footer logo, Social media (facebook, twitter, skype, google+,instagram), Footer Content, Con …
Is General Options Safe to Use in 2026?
Use With Caution
Score 63/100General Options has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "general-options" plugin v1.1.0 presents a generally good security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code demonstrates strong security practices by exclusively using prepared statements for SQL queries and a high percentage of properly escaped output. The presence of nonce checks is also a positive indicator of security awareness.
However, the analysis does reveal some areas for potential improvement. A notable concern is the complete lack of capability checks, which means that even protected actions (if any existed) would not be verified against user roles. While there are no identified critical or high severity taint flows, the 20% of improperly escaped output, though not explicitly detailed as a vulnerability, could still lead to cross-site scripting (XSS) issues in certain contexts. The plugin also has no recorded vulnerability history, which is a strength but doesn't guarantee future immunity.
In conclusion, "general-options" v1.1.0 is a relatively secure plugin with a minimal attack surface and good handling of database interactions and output. The primary area of concern is the absence of capability checks, which leaves it open to privilege escalation if any protected functionality were to be introduced in the future. The small percentage of unescaped output should also be addressed to further harden the plugin against potential XSS.
Key Concerns
- No capability checks found
- 20% of output not properly escaped
General Options Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
General Options <= 1.1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'ad_contact_number' Parameter
General Options Release Timeline
General Options Code Analysis
Output Escaping
Data Flow Analysis
General Options Attack Surface
WordPress Hooks 4
Maintenance & Trust
General Options Maintenance & Trust
Maintenance Signals
Community Trust
General Options Alternatives
Any Custom Fields
any-custom-field
Any Custom fields provide the options to customize in wordpress front end website.
Global Content Manager
global-content-manager
The simple and best plugin for making global sections WordPress.
Product Options and Price Calculation Formulas for WooCommerce – Uni CPO
uni-woo-custom-product-options
Offers the ability to add extra product options and calculate the price dynamically based on the selected options using custom mathematical formulas!
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Redux Framework
redux-framework
Redux is a simple, truly extensible, and fully responsive options framework for WordPress themes and plugins. It ships with an integrated demo.
General Options Developer Profile
1 plugin · 10 total installs
How We Detect General Options
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/general-options/assets/css/bootstrap.min.css/wp-content/plugins/general-options/assets/css/ad_custom-admin.css/wp-content/plugins/general-options/assets/font-awesome/css/font-awesome.min.css/wp-content/plugins/general-options/js/wp-media-upload.jsgeneral-options/assets/css/bootstrap.min.css?ver=general-options/assets/css/ad_custom-admin.css?ver=general-options/assets/font-awesome/css/font-awesome.min.css?ver=general-options/js/wp-media-upload.js?ver=