Transients Security & Risk Analysis

wordpress.org/plugins/leira-transients

Inspect, edit, and delete WordPress transients from Tools -> Transients.

0 active installs v1.0.5 PHP 8.3+ WP 4.1+ Updated Feb 24, 2026
admin-toolsdeveloper-toolsoptimizationtransients
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Transients Safe to Use in 2026?

Generally Safe

Score 100/100

Transients has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "leira-transients" v1.0.5 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries, using prepared statements exclusively, and has a very high rate of properly escaped output. Furthermore, the absence of any recorded vulnerabilities or CVEs in its history suggests a history of relatively secure development. However, the plugin has significant security concerns related to its attack surface. It exposes two AJAX handlers, both of which lack authentication checks. This directly translates to two critical taint flows with unsanitized paths, indicating a high risk of unauthorized actions or data manipulation through these unprotected entry points. While the presence of nonce checks and capability checks on some code paths is encouraging, the two unprotected AJAX handlers represent a substantial security weakness that needs immediate attention.

Key Concerns

  • AJAX handlers without auth checks
  • Taint flows with unsanitized paths
Vulnerabilities
None known

Transients Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Transients Release Timeline

v1.0.5Current
v1.0.4
v1.0.3
Code Analysis
Analyzed Apr 16, 2026

Transients Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
2
74 escaped
Nonce Checks
2
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

97% escaped76 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
search_box (admin/class-list-table.php:212)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Transients Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_leira-transient-saveincludes/class-plugin.php:140
authwp_ajax_leira-transients-footer-ratedincludes/class-plugin.php:146
WordPress Hooks 5
actionplugins_loadedincludes/class-plugin.php:125
actionadmin_enqueue_scriptsincludes/class-plugin.php:137
actionadmin_menuincludes/class-plugin.php:138
filterset-screen-optionincludes/class-plugin.php:139
filteradmin_footer_textincludes/class-plugin.php:145
Maintenance & Trust

Transients Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version8.3
Downloads306

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Transients Developer Profile

Ariel

5 plugins · 9K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
12 days
View full developer profile
Detection Fingerprints

How We Detect Transients

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leira-transients/build/admin.css/wp-content/plugins/leira-transients/build/admin.js

HTML / DOM Fingerprints

CSS Classes
leira-transients-search
Data Attributes
id="leira-transients-search"
FAQ

Frequently Asked Questions about Transients