
Hide This Security & Risk Analysis
wordpress.org/plugins/hide-thisThis plugin provides a shortcode that lets you hide some parts of the content from your posts and pages.
Is Hide This Safe to Use in 2026?
Generally Safe
Score 85/100Hide This has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hide-this" plugin v1.1.3 presents a generally positive security posture based on the static analysis. The code demonstrates good development practices, with all SQL queries using prepared statements and all outputs being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further reduces the potential attack surface. Critically, there are no identified taint flows, suggesting that user input is not being mishandled in a way that could lead to code execution or data compromise. The plugin also has a clean vulnerability history with no recorded CVEs, indicating a history of stable and secure development.
However, a key area of concern is the lack of nonce checks. While the plugin has a capability check, the absence of nonce validation on its entry points (shortcodes in this case) could potentially leave it vulnerable to Cross-Site Request Forgery (CSRF) attacks if the shortcode's functionality could be leveraged by an attacker to perform unauthorized actions on behalf of a logged-in user. The attack surface itself is small and all entry points appear to have some form of protection (capability check), which is a strength. Nonetheless, the missing nonce checks represent a specific, albeit potentially minor depending on the shortcode's function, risk that should be addressed.
Key Concerns
- Missing nonce checks on shortcodes
Hide This Security Vulnerabilities
Hide This Code Analysis
Hide This Attack Surface
Shortcodes 2
Maintenance & Trust
Hide This Maintenance & Trust
Maintenance Signals
Community Trust
Hide This Alternatives
Hidden Comment Field
hidden-field-to-comments
Hidden Comment Field provides functionality to block more spam by adding hidden field with jquery
Advanced Access Manager – Access Governance for WordPress
advanced-access-manager
Access Governance for WordPress. Control roles, users, content, admin areas, and APIs to prevent broken access controls and excessive privileges.
WPFront User Role Editor
wpfront-user-role-editor
Easily allows you to manage WordPress user roles. You can create, edit, delete and manage capabilities, also copy existing roles.
Hide Admin Bar Based on User Roles
hide-admin-bar-based-on-user-roles
Hide the WordPress Admin Bar for specific user roles, capabilities, devices, pages, or time windows. The ultimate toolbar control plugin for membershi …
Hide Admin Menu
hide-admin-menu
Using this plugin, we can hide the admin menu easily.
Hide This Developer Profile
4 plugins · 3K total installs
How We Detect Hide This
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[hide][/hide][hidethis][/hidethis]