Limited Editor Security & Risk Analysis

wordpress.org/plugins/limited-editor

Adds a new user role \"Limited editor\" to WordPress when the plugin is activated. After that, the plugin can be removed.

0 active installs v1.1 PHP + WP 4.3+ Updated Dec 10, 2025
limited-editornew-roleseo-editoruser-permissions
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Limited Editor Safe to Use in 2026?

Generally Safe

Score 100/100

Limited Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "limited-editor" plugin version 1.1 exhibits an exceptionally strong security posture. The static analysis reveals a complete absence of identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that lack appropriate authentication or permission checks. Furthermore, the code demonstrates excellent security practices with no dangerous functions detected, all SQL queries utilizing prepared statements, and all outputs being properly escaped. There are no file operations or external HTTP requests to scrutinize, and critically, no nonce or capability checks are needed because there are no exposed entry points. Taint analysis also shows no concerning data flows.

The vulnerability history reinforces this positive assessment, showing a complete lack of any recorded CVEs. This, coupled with the clean static analysis, suggests a plugin developed with a strong emphasis on security and best practices. However, the complete absence of any checks or entry points, while secure by definition, also implies a very limited functionality that does not interact with WordPress in ways that typically require security measures. Therefore, the plugin appears to be secure due to its lack of features that would expose it to common vulnerabilities. There are no identified weaknesses or risks based on the provided data.

Vulnerabilities
None known

Limited Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Limited Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Limited Editor Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Limited Editor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 10, 2025
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Limited Editor Developer Profile

Gerard Blanco

2 plugins · 3K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Limited Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Limited Editor