
I don't endorse Google Security & Risk Analysis
wordpress.org/plugins/i-dont-endorse-googleAdd rel="nofollow" to all links going to .Google..
Is I don't endorse Google Safe to Use in 2026?
Generally Safe
Score 85/100I don't endorse Google has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "i-dont-endorse-google" plugin v1.0.3 exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of any reported CVEs, combined with the fact that all SQL queries use prepared statements and all output is properly escaped, suggests a developer mindful of common web vulnerabilities. Furthermore, the plugin has no observable attack surface via AJAX, REST API, shortcodes, or cron events, and no file operations or external HTTP requests are made. This significantly limits the potential avenues for exploitation.
However, a critical concern arises from the presence of the `create_function` function. While the static analysis does not show any taint flows originating from this function or indicate it's being used in a way that directly leads to a vulnerability in this specific version, `create_function` is deprecated and notoriously unsafe due to its ability to execute arbitrary PHP code, often leading to severe security risks if not handled with extreme caution and strict sanitization. The lack of capability checks and nonce checks also presents a potential weakness, especially if the plugin were to be extended or if its functionality were to change in the future.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in areas like SQL and output escaping, the use of `create_function` introduces a significant inherent risk. The limited attack surface and lack of vulnerabilities in the current version are positive, but the potential for misuse of `create_function` warrants attention and suggests that while the current state may appear secure, there's a latent risk that could be exploited under different circumstances or with future modifications. A review of how `create_function` is actually utilized within the plugin is highly recommended.
Key Concerns
- Use of deprecated and unsafe create_function
- Missing nonce checks
- Missing capability checks
I don't endorse Google Security Vulnerabilities
I don't endorse Google Code Analysis
Dangerous Functions Found
I don't endorse Google Attack Surface
WordPress Hooks 2
Maintenance & Trust
I don't endorse Google Maintenance & Trust
Maintenance Signals
Community Trust
I don't endorse Google Alternatives
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
seo-by-rank-math
Rank Math SEO is the best WordPress SEO plugin with the features of many SEO and AI SEO tools in a single package to help multiply your SEO traffic.
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy)
google-analytics-for-wordpress
The best free Google Analytics plugin for WordPress. See how visitors find and use your website so you can grow your business with powerful analytics.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
I don't endorse Google Developer Profile
6 plugins · 1K total installs
How We Detect I don't endorse Google
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.