Improve Website Security Security & Risk Analysis

wordpress.org/plugins/improve-website-security

This plugin enhances WordPress security by implementing measures like Security Headers, changing the Login URL, disabling WP JSON API, and more.

40 active installs v1.0.1 PHP 7.0+ WP 5.5+ Updated Dec 4, 2025
change-default-login-pagedisable-right-clickdisable-json-apisecurity-headerssolid-wp-security-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Improve Website Security Safe to Use in 2026?

Generally Safe

Score 100/100

Improve Website Security has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'improve-website-security' plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL query sanitization and output escaping, with 100% of both being handled correctly. The absence of known vulnerabilities in its history is also a strong indicator of a well-maintained and secure codebase. However, the plugin introduces significant risks due to its attack surface. Two AJAX handlers are present, and alarmingly, neither includes an authentication check. This directly exposes these entry points to potential exploitation by unauthenticated users, which is a critical security concern. The taint analysis also revealed two flows with unsanitized paths, although thankfully without critical or high severity, this still indicates potential avenues for data manipulation or injection if not properly validated and sanitized further down the processing chain. The lack of capability checks further exacerbates the risk associated with unprotected AJAX handlers, as they could be triggered by any user, regardless of their role or permissions.

Key Concerns

  • AJAX handlers without authentication
  • AJAX handlers without capability checks
  • Flows with unsanitized paths (taint analysis)
Vulnerabilities
None known

Improve Website Security Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Improve Website Security Release Timeline

v1.0.1Current
Code Analysis
Analyzed Apr 16, 2026

Improve Website Security Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
233 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped233 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
send_login_email_improve_website_security_itc (includes/class-login-email-alerts.php:6)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Improve Website Security Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_improve_wp_Security_itc_dismissedincludes/class-itc.php:143
authwp_ajax_improve_wp_Security_itc_dismissed_alertincludes/class-itc.php:144
WordPress Hooks 34
actionadmin_noticesadmin/class-admin.php:14
actionplugins_loadedimprove-website-security.php:62
actionadmin_noticesincludes/class-activator.php:41
filterrest_authentication_errorsincludes/class-disable-rest-api.php:13
filterjson_enabledincludes/class-disable-rest-api.php:69
filterjson_jsonp_enabledincludes/class-disable-rest-api.php:70
filterrest_enabledincludes/class-disable-rest-api.php:71
filterrest_jsonp_enabledincludes/class-disable-rest-api.php:72
actionplugins_loadedincludes/class-itc.php:46
actionsend_headersincludes/class-itc.php:56
filterwp_headersincludes/class-itc.php:57
actioninitincludes/class-itc.php:58
actioninitincludes/class-itc.php:64
filterlogin_errorsincludes/class-itc.php:73
actionrest_authentication_errorsincludes/class-itc.php:80
actionxmlrpc_methodsincludes/class-itc.php:87
actionwp_enqueue_scriptsincludes/class-itc.php:94
actionwp_enqueue_scriptsincludes/class-itc.php:102
actionwp_loginincludes/class-itc.php:109
actionlogin_headincludes/class-itc.php:117
actioninitincludes/class-itc.php:118
actionwp_logoutincludes/class-itc.php:119
actionlostpassword_urlincludes/class-itc.php:120
actiontemplate_redirectincludes/class-itc.php:128
actionadmin_enqueue_scriptsincludes/class-itc.php:138
actionadmin_enqueue_scriptsincludes/class-itc.php:139
actionadmin_menuincludes/class-itc.php:140
actionadmin_initincludes/class-itc.php:141
actionadmin_noticesincludes/class-itc.php:145
actionwp_enqueue_scriptsincludes/class-itc.php:150
actionwp_enqueue_scriptsincludes/class-itc.php:151
actionadmin_noticesincludes/class-login-email-alerts.php:11
actionupdate_option_change_admin_url_improve_website_security_itcincludes/rewrite-handler-itc.php:4
actionupdate_option_itc_plugin_deactivation_secret_improve_website_security_itcincludes/rewrite-handler-itc.php:5
Maintenance & Trust

Improve Website Security Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version7.0
Downloads811

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Improve Website Security Developer Profile

ideasToCode

6 plugins · 13K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
390 days
View full developer profile
Detection Fingerprints

How We Detect Improve Website Security

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/improve-website-security/admin/css/itc-admin-improve-website-security.css/wp-content/plugins/improve-website-security/admin/js/itc-admin-improve-website-security.js
Script Paths
/wp-content/plugins/improve-website-security/admin/js/itc-admin-improve-website-security.js
Version Parameters
improve-website-security/admin/css/itc-admin-improve-website-security.css?ver=improve-website-security/admin/js/itc-admin-improve-website-security.js?ver=

HTML / DOM Fingerprints

CSS Classes
improve-website-security
JS Globals
Improve_WP_Security_ITC_Admin
FAQ

Frequently Asked Questions about Improve Website Security