
The Official HideReferrer.com WP Plugin Security & Risk Analysis
wordpress.org/plugins/hidereferrerNo. This plugin does not modify the source of your post or page. Links are modified in the user's browser.
Is The Official HideReferrer.com WP Plugin Safe to Use in 2026?
Generally Safe
Score 100/100The Official HideReferrer.com WP Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hidereferrer" plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals indicate good practices in crucial areas like SQL query handling, with all queries utilizing prepared statements, and a capability check present. The lack of file operations and external HTTP requests also reduces potential exposure points.
However, a significant concern arises from the low percentage of properly escaped output (29%). This suggests that data processed and outputted by the plugin may not be adequately sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is echoed directly. The absence of nonces on any potential entry points (though there are none listed) would also be a concern in a more complex plugin, but given the zero attack surface here, it's less of an immediate threat. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. This, combined with the limited attack surface and secure SQL handling, suggests a generally well-developed plugin. The primary weakness lies in the output escaping, which should be addressed to achieve a more robust security profile.
Key Concerns
- Low percentage of properly escaped output
The Official HideReferrer.com WP Plugin Security Vulnerabilities
The Official HideReferrer.com WP Plugin Code Analysis
Output Escaping
The Official HideReferrer.com WP Plugin Attack Surface
WordPress Hooks 5
Maintenance & Trust
The Official HideReferrer.com WP Plugin Maintenance & Trust
Maintenance Signals
Community Trust
The Official HideReferrer.com WP Plugin Alternatives
The Official HideReferrer.com WP Plugin Developer Profile
1 plugin · 0 total installs
How We Detect The Official HideReferrer.com WP Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hidereferrer/assets/app.js/wp-content/plugins/hidereferrer/assets/app.jsHTML / DOM Fingerprints
referrer_linkhide_mode_allhide_mode_post_pagehide_mode_commentshide_mode_all_comments_adminexceptions