
Great Feature Toggle – Feature Flags for WordPress Security & Risk Analysis
wordpress.org/plugins/great-feature-toggleGreat Feature Toggle is a WordPress feature toggle and feature flag plugin that lets administrators enable or disable WordPress features such as conta …
Is Great Feature Toggle – Feature Flags for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Great Feature Toggle – Feature Flags for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "great-feature-toggle" v6.5.6 plugin exhibits a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, SQL queries that are not prepared, and a high percentage of properly escaped output are excellent indicators of secure coding practices. Furthermore, the plugin demonstrates a commitment to security by implementing nonce and capability checks on its entry points, and the taint analysis revealed no critical or high-severity vulnerabilities, suggesting that user-supplied data is handled with appropriate sanitization.
The plugin's vulnerability history is also remarkably clean, with zero recorded CVEs. This lack of historical vulnerabilities, coupled with the current static analysis findings, strongly suggests a well-maintained and security-conscious development process. The plugin appears to have a limited attack surface, with only two shortcodes as entry points and no unprotected handlers or routes. The presence of file operations and external HTTP requests, while present, do not appear to be directly linked to any identified security risks in this analysis.
Overall, this plugin presents a very low-risk profile. Its strengths lie in its robust security implementations within the code, such as proper escaping and robust checking mechanisms, and its clean historical record. While no security concerns are directly flagged in this analysis, vigilance is always recommended for any software. The absence of concerns here should be viewed as a positive sign, but future updates should continue to adhere to these high security standards.
Great Feature Toggle – Feature Flags for WordPress Security Vulnerabilities
Great Feature Toggle – Feature Flags for WordPress Code Analysis
Output Escaping
Data Flow Analysis
Great Feature Toggle – Feature Flags for WordPress Attack Surface
Shortcodes 2
WordPress Hooks 34
Maintenance & Trust
Great Feature Toggle – Feature Flags for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Great Feature Toggle – Feature Flags for WordPress Alternatives
Feature Flags
feature-flags
Feature flags allows developers to configure features behind the feature flags on both Server(PHP) and Client(JS/TS) side.
Beta Flags … now with A/B Testing!
beta-flags
Thanks to: James Williams, whose plugin inspired this one (https://github.com/jamesrwilliams/feature-flags)
Switcheroo
switcheroo
Easily manage feature flags to control the availability of features on your WordPress site without deploying new code.
Great Feature Toggle – Feature Flags for WordPress Developer Profile
1 plugin · 0 total installs
How We Detect Great Feature Toggle – Feature Flags for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/great-feature-toggle/gft-admin.css/wp-content/plugins/great-feature-toggle/gft-admin.js/wp-content/plugins/great-feature-toggle/gft-core.js/wp-content/plugins/great-feature-toggle/gft-admin.js/wp-content/plugins/great-feature-toggle/gft-core.jsgreat-feature-toggle/gft-admin.css?ver=great-feature-toggle/gft-admin.js?ver=great-feature-toggle/gft-core.js?ver=HTML / DOM Fingerprints
gft-admin-wrapgft-settings-sectiongft-feature-togglecf-messagecf-message-errorcf-message-success<!-- Silence is golden. --><!-- GFT Debug Start --><!-- GFT Debug End --><!-- GFT Settings Form -->+2 moredata-gft-featuredata-gft-setting-namedata-gft-setting-valuewindow.gftSettingswindow.gftAdmin<form method='post' class='grftg-contact-form'><input type='hidden' name='cf_submitted' value='1'><input type='hidden' name='grftg_cfs_nonce' value='<label for='cf_name'>Name:</label>