Hide Plugins Security & Risk Analysis

wordpress.org/plugins/hide-plugins

Hide installed plugins from clients and other admin users.

1K active installs v1.0.4 PHP + WP 3.0+ Updated Apr 22, 2016
admindashboardhiddenhideplugins
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEDec 31, 2025
Safety Verdict

Is Hide Plugins Safe to Use in 2026?

Use With Caution

Score 63/100

Hide Plugins has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Dec 31, 2025Updated 9yr ago
Risk Assessment

The "hide-plugins" v1.0.4 plugin exhibits a strong static security posture with no identified dangerous functions, SQL queries utilizing prepared statements, properly escaped output, and no file operations or external HTTP requests. The complete absence of identified taint flows, including critical or high severity ones, further reinforces this positive impression. However, the plugin's security is significantly undermined by its vulnerability history. The presence of one known, unpatched CVE, specifically a medium severity "Missing Authorization" vulnerability, is a critical concern. This indicates a historical weakness in how the plugin handles user permissions, which, despite current static analysis findings, may still represent a latent risk. The fact that this vulnerability is recent (dated 2025) and unpatched is particularly worrying, suggesting ongoing exposure. While the code analysis itself is reassuring, the outstanding vulnerability forces a cautious approach.

Key Concerns

  • Unpatched CVE present (medium severity)
Vulnerabilities
1

Hide Plugins Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62115medium · 4.3Missing Authorization

Hide Plugins <= 1.0.4 - Missing Authorization

Dec 31, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Hide Plugins Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Hide Plugins Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninithide-plugins.php:43
filteroption_hide_pluginshide-plugins.php:44
filterall_pluginshide-plugins.php:45
filterplugin_action_linkshide-plugins.php:46
actionadmin_action_hide_pluginhide-plugins.php:47
actionadmin_action_show_pluginhide-plugins.php:48
filternetwork_admin_plugin_action_linkshide-plugins.php:51
Maintenance & Trust

Hide Plugins Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 22, 2016
PHP min version
Downloads19K

Community Trust

Rating96/100
Number of ratings9
Active installs1K
Developer Profile

Hide Plugins Developer Profile

ThemeBoy

12 plugins · 21K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
360 days
View full developer profile
Detection Fingerprints

How We Detect Hide Plugins

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Hide Plugins