
GP Last Update Security & Risk Analysis
wordpress.org/plugins/gp-last-updateA plugin for GlotPress as a WordPress plugin that adds a column to the translation set list to display the last time they were updated.
Is GP Last Update Safe to Use in 2026?
Generally Safe
Score 85/100GP Last Update has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gp-last-update" v1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface, and crucially, all identified entry points (if any existed) appear to have authentication checks. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. The presence of a capability check is also a positive sign for access control.
However, a significant concern arises from the output escaping. With one total output and 0% properly escaped, there is a clear risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that is not properly sanitized before rendering could be exploited by attackers. The lack of any identified taint flows is a positive, but this does not negate the direct output escaping issue.
Furthermore, the complete absence of known vulnerabilities in its history is encouraging, suggesting a well-maintained or simple plugin. The fact that there are no recorded vulnerabilities and no common vulnerability types further reinforces this. In conclusion, while the plugin's limited attack surface and secure coding practices in areas like SQL are commendable, the critical lack of output escaping presents a notable risk that must be addressed.
Key Concerns
- No output escaping
GP Last Update Security Vulnerabilities
GP Last Update Release Timeline
GP Last Update Code Analysis
Output Escaping
GP Last Update Attack Surface
WordPress Hooks 2
Maintenance & Trust
GP Last Update Maintenance & Trust
Maintenance Signals
Community Trust
GP Last Update Alternatives
Localize WordPress
localize
Easily switch to any localization from GlotPress
WP Translation Status
wp-translation
Make a link to GlotPress centralised translation so contributor can help translating the plugin that do not have yet a translation in the local site l …
GP Remove Powered By
gp-removed-powered-by
A plugin for GlotPress as a WordPress plugin that removes the "Powered By" in the footer.
GP Additional Links
gp-additional-links
A plugin for GlotPress as a WordPress plugin that adds a link to the WordPress dashboard for admins in the GlotPress page as well as a link to the Glo …
GP Download Name
gp-download-name
A plugin for GlotPress that uses a customizable template for the download file name.
GP Last Update Developer Profile
35 plugins · 8K total installs
How We Detect GP Last Update
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
Last updated on Never updated<br>