GreenerWP Security & Risk Analysis

wordpress.org/plugins/greenerwp

Assists you in creating climate-friendly WordPress websites.

60 active installs v0.2.4 PHP 7.0+ WP 5.2.3+ Updated Nov 16, 2023
analysisclimateperformanceseosustainability
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GreenerWP Safe to Use in 2026?

Generally Safe

Score 85/100

GreenerWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The greenerwp v0.2.4 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any identified critical or high-severity taint flows, dangerous functions, or file operations is a strong positive indicator. The plugin also appears to have a minimal attack surface, with no directly exposed AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks. Furthermore, the lack of any recorded vulnerabilities in its history suggests a history of secure development or diligent patching.

However, there are areas for improvement. The low percentage of properly escaped output (7%) is a significant concern, as it increases the risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. While the SQL queries show a decent percentage using prepared statements (64%), the remaining 36% could still be a vector for SQL injection if sensitive data is involved. The absence of nonce checks on any entry points, though the attack surface is currently zero, indicates a potential oversight in implementing WordPress's security mechanisms that could be exploited if new entry points are added without proper checks.

In conclusion, greenerwp v0.2.4 demonstrates strengths in its limited attack surface and clean vulnerability history. The main weaknesses lie in output escaping and the potential for SQL injection in queries not using prepared statements, along with the absence of nonce checks. Addressing these specific areas would significantly enhance the plugin's overall security.

Key Concerns

  • Low percentage of properly escaped output
  • Significant portion of SQL queries not prepared
  • No nonce checks on entry points
Vulnerabilities
None known

GreenerWP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GreenerWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
9 prepared
Unescaped Output
13
1 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

64% prepared14 total queries

Output Escaping

7% escaped14 total outputs
Attack Surface

GreenerWP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
actionplugins_loadedgreenerwp.php:75
filterthe_contentsrc\Images\PreviewFilter.php:19
filterpost_thumbnail_htmlsrc\Images\PreviewFilter.php:20
actionadmin_initsrc\Profiling\PageViews.php:19
actionrest_api_initsrc\UI\Admin\AnalysisController.php:14
actionadmin_menusrc\UI\Admin\Page.php:19
actionadmin_menusrc\UI\Admin\Recipes.php:17
actionwp_footersrc\UI\Admin\Recipes.php:18
actionrest_api_initsrc\UI\Admin\RecipesController.php:13
actionadmin_bar_menusrc\UI\Admin\ScannerLinks.php:12
actionadmin_menusrc\UI\Admin\Settings.php:17
actionwp_footersrc\UI\Admin\Settings.php:18
actionrest_api_initsrc\UI\Admin\SettingsController.php:13
actionadmin_menusrc\UI\Admin\Statistics.php:20
actionrest_api_initsrc\UI\Admin\StatisticsController.php:17
actionrest_api_initsrc\UI\Frontend\ProfilerController.php:14
actionwp_headsrc\UI\Frontend\Tweaks\DisableWebFonts.php:10
filterjpeg_qualitysrc\UI\Frontend\Tweaks\JPEGQuality.php:11
filterwpcf7_load_jssrc\UI\Frontend\Tweaks\Plugins\WPCF7.php:12
filterwpcf7_load_csssrc\UI\Frontend\Tweaks\Plugins\WPCF7.php:13
actionwp_enqueue_scriptssrc\UI\Frontend\Tweaks\Plugins\WPCF7.php:14
actionwidgets_initsrc\UI\Frontend\Widgets\Awareness.php:20
actionwp_enqueue_scriptssrc\UI\Frontend.php:50
actionadmin_enqueue_scriptssrc\UI\Frontend.php:51
actionwpsrc\UI\Frontend.php:52
Maintenance & Trust

GreenerWP Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedNov 16, 2023
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

GreenerWP Developer Profile

Christian Neumann

2 plugins · 5K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
753 days
View full developer profile
Detection Fingerprints

How We Detect GreenerWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/greenerwp/frontend.css/wp-content/plugins/greenerwp/frontend.js
Script Paths
/wp-content/plugins/greenerwp/frontend.js
Version Parameters
greenerwp/frontend.css?ver=greenerwp/frontend.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- greenerwp caching check -->
JS Globals
greenerwpVars
FAQ

Frequently Asked Questions about GreenerWP