
Guten Free Options Security & Risk Analysis
wordpress.org/plugins/guten-free-optionsGutenberg Free Options for your WordPressed Burger err I mean Editor.
Is Guten Free Options Safe to Use in 2026?
Use With Caution
Score 58/100Guten Free Options has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The 'guten-free-options' plugin version 0.9.7 exhibits a concerning security posture despite some positive indicators. While the plugin demonstrates excellent practices in output escaping, with 100% of outputs properly escaped, and makes good use of prepared statements for SQL queries (89%), it suffers from a significant vulnerability in its handling of entry points.
The static analysis reveals a total of 4 AJAX handlers, alarmingly, all 4 lack authentication checks. This presents a substantial attack surface without any protective measures. Furthermore, the taint analysis highlights a high severity flow with unsanitized input, indicating a potential risk of data manipulation or unauthorized actions. The presence of 5 unsanitized paths in the taint analysis, even without a critical severity finding, warrants attention.
The plugin's vulnerability history is a major red flag. It has two known medium severity CVEs, both of which are currently unpatched. The common vulnerability type being Cross-site Scripting, coupled with the fact that the last vulnerability was very recent (2025-01-17), strongly suggests recurring issues with input sanitization or improper neutralization of data. This pattern of unpatched vulnerabilities indicates a lack of proactive security maintenance and a potential ongoing risk to user data and site integrity.
Key Concerns
- Unprotected AJAX handlers
- Unpatched CVEs (2 medium)
- High severity taint flow
- Unsanitized paths in taint analysis
Guten Free Options Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Guten Free Options <= 0.9.5 - Reflected Cross-Site Scripting
Guten Free Options <= 0.9.5 - Reflected Cross-Site Scripting
Guten Free Options Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Guten Free Options Attack Surface
AJAX Handlers 4
WordPress Hooks 61
Maintenance & Trust
Guten Free Options Maintenance & Trust
Maintenance Signals
Community Trust
Guten Free Options Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Disable Gutenberg
disable-gutenberg
Disable Gutenberg Block Editor and restore the Classic Editor and original Edit Post screen (TinyMCE, meta boxes, etc.).
Classic Editor and Classic Widgets
classic-editor-and-classic-widgets
Disables Gutenberg editor totally everywhere and enables Classic Editor and Classic Widgets.
Enable Classic Editor & Widgets
enable-classic-editor
A simple & lightweight plugin to enable the classic editor on WordPress with advanced configuration options.
Guten Free Options Developer Profile
5 plugins · 250 total installs
How We Detect Guten Free Options
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/guten-free-options/css/guten-free-options.css/wp-content/plugins/guten-free-options/css/guten-free-options-lite.css/wp-content/plugins/guten-free-options/js/guten-free-options.js/wp-content/plugins/guten-free-options/js/guten-free-options.jsguten-free-options/css/guten-free-options.css?ver=guten-free-options/css/guten-free-options-lite.css?ver=guten-free-options/js/guten-free-options.js?ver=HTML / DOM Fingerprints
guten-free-options-settings<!-- Guten Free Options Settings --><!-- Guten Free Options Network Settings --><!-- Guten Free Options Update Checker --><!-- Guten Free Options Freemius Loader -->+2 moredata-guten-free-options-slugguten_free_options_data