Limit Revisions Security & Risk Analysis

wordpress.org/plugins/limit-revisions

This plugin adds a new setting in the last position of Settings > General, this option will allow you to select limit of revisions that WordPress s …

1K active installs v1.0.0 PHP 5.2.4+ WP 4.0+ Updated Feb 23, 2023
contentlimitrevisionrevisions
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Limit Revisions Safe to Use in 2026?

Generally Safe

Score 85/100

Limit Revisions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "limit-revisions" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs and the clean slate in taint analysis suggest a well-developed and likely secure codebase. Notably, there are no identified attack vectors such as AJAX handlers, REST API routes, or shortcodes, which significantly reduces the plugin's external exposure. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, further mitigating common attack vectors.

However, a significant concern arises from the lack of nonce checks and capability checks. While the plugin's attack surface appears minimal, the absence of these crucial security mechanisms means that any functionality, should it be discovered or introduced in the future, would be vulnerable to unauthorized access and manipulation. The output escaping, while mostly proper, has some instances that are not, which could potentially lead to cross-site scripting (XSS) vulnerabilities if those outputs are rendered in a user-facing context. The very low attack surface and lack of historical vulnerabilities are strengths, but the missing authentication and authorization checks represent a substantial weakness that could be exploited if the plugin's functionality were to grow or if unforeseen interaction points emerge.

Key Concerns

  • No nonce checks present
  • No capability checks present
  • Some output not properly escaped
Vulnerabilities
None known

Limit Revisions Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Limit Revisions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped4 total outputs
Attack Surface

Limit Revisions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionplugins_loadedlimit-wordpress-revisions.php:14
actionadmin_initlimit-wordpress-revisions.php:19
actionplugins_loadedlimit-wordpress-revisions.php:20
Maintenance & Trust

Limit Revisions Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedFeb 23, 2023
PHP min version5.2.4
Downloads6K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

Limit Revisions Developer Profile

Carlos Martínez Romero

9 plugins · 5K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Limit Revisions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
description
FAQ

Frequently Asked Questions about Limit Revisions