
Log Deprecated Notices Security & Risk Analysis
wordpress.org/plugins/log-deprecated-noticesLogs the usage of deprecated files, functions, and function arguments, and identifies where the deprecated functionality is being used.
Is Log Deprecated Notices Safe to Use in 2026?
Generally Safe
Score 85/100Log Deprecated Notices has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "log-deprecated-notices" plugin v0.4.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed, and no external HTTP requests or file operations. The absence of any known vulnerabilities (CVEs) in its history is also a strong indicator of good maintenance and security practices. However, there are significant areas of concern within the code itself.
The analysis shows a concerningly low percentage of SQL queries using prepared statements (54%), suggesting a potential risk of SQL injection vulnerabilities if the unsanitized path identified in the taint analysis is related to these queries. Furthermore, only 33% of output is properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without adequate sanitization.
While the plugin has no known CVEs and a clean vulnerability history, this does not negate the inherent risks identified in the code. The lack of capability checks and nonce checks, coupled with the identified unsanitized path, presents opportunities for attackers, especially in scenarios where the plugin might interact with user-controllable data. The overall conclusion is that while the plugin has a limited attack surface and a good historical security record, the implementation details regarding SQL query preparation and output escaping require immediate attention to mitigate potential security weaknesses.
Key Concerns
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- Flow with unsanitized paths
- Missing nonce checks
- Missing capability checks
Log Deprecated Notices Security Vulnerabilities
Log Deprecated Notices Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Log Deprecated Notices Attack Surface
WordPress Hooks 18
Maintenance & Trust
Log Deprecated Notices Maintenance & Trust
Maintenance Signals
Community Trust
Log Deprecated Notices Alternatives
Log Deprecated Notices Extender
log-deprecated-notices-extender
This developer-oriented WordPress plugin extends Andrew Nacin's Log Deprecated Notices to show a link in the WP 3.3+ Toolbar.
Unnotifier — disable admin notices individually
unnotifier
Disable admin notices individually or completely. Smart plugin detection, flexible modes, clean dashboard cleanup. Free & lightweight solution.
Debug Bar – Enable WP_DEBUG from admin dashboard
enable-wp-debug-from-admin-dashboard
[ ✅ 𝐒𝐄𝐂𝐔𝐑𝐄 𝐏𝐋𝐔𝐆𝐈𝐍𝐒 b𝓎 𝒫𝓊𝓋𝑜𝓍] You can easily enable WP_DEBUG using a toolbar button. READ DESCRIPTION!
Disable Deprecated Warnings
disable-deprecated-warnings
Prevents plugins from showing deprecated errors in the WordPress admin.
Issues Tracker
issues-tracker
Issues Tracker allows you view and search WordPress logs, receive security advice, track 404 errors, and view your server settings.
Log Deprecated Notices Developer Profile
6 plugins · 22K total installs
How We Detect Log Deprecated Notices
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/log-deprecated-notices/log-deprecated-notices.php