Hidden Plugin Security & Risk Analysis

wordpress.org/plugins/hidden-plugin

Hidden Plugin is a light-weight plugin that gives a single admin user the ability to hide plugins prevent them from being activated, deactivated, or d …

10 active installs v1.0 PHP 5.2.4+ WP 3.0.1+ Updated Dec 11, 2018
admindashboardhiddenhidden-pluginshideplugins
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hidden Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Hidden Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin 'hidden-plugin' v1.0 exhibits a generally strong security posture, with no identified vulnerabilities in its history and a clean static analysis report regarding dangerous functions, SQL injection risks, and external requests. The absence of identified CVEs further reinforces this positive outlook. However, a notable concern arises from the low percentage of properly escaped output. With 12 total outputs analyzed and only 33% being properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin has a limited attack surface and no critical taint flows were detected, the lack of robust output escaping practices represents a tangible weakness that could be exploited. The presence of Select2, a bundled library, also introduces a potential risk if it's an outdated version, though its specific version is not provided for a definitive assessment.

Key Concerns

  • Low percentage of properly escaped output
  • Bundled library (Select2) potentially outdated
Vulnerabilities
None known

Hidden Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hidden Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

33% escaped12 total outputs
Attack Surface

Hidden Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menu0.0.1\hidden-plugin.php:20
actionwp_enqueue_scripts0.0.1\hidden-plugin.php:21
actionadmin_init0.0.1\hidden-plugin.php:30
filterall_plugins0.0.1\hidden-plugin.php:31
actionadmin_menuhidden-plugin.php:20
actionwp_enqueue_scriptshidden-plugin.php:21
actionadmin_inithidden-plugin.php:30
filterall_pluginshidden-plugin.php:31
Maintenance & Trust

Hidden Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 11, 2018
PHP min version5.2.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Hidden Plugin Developer Profile

Shiyar Suresh

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hidden Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hidden-plugin/assets/css/jquery.ultraselect.min.css/wp-content/plugins/hidden-plugin/assets/js/ultraselect.js
Script Paths
/wp-content/plugins/hidden-plugin/assets/js/ultraselect.js

HTML / DOM Fingerprints

CSS Classes
ultraselect
Data Attributes
data-ultraselect
JS Globals
jQuery
FAQ

Frequently Asked Questions about Hidden Plugin