Manage Inactive Subsites Security & Risk Analysis

wordpress.org/plugins/manage-inactive-subsites

Allow automate handle status of inactive site in MultiSite installation.

0 active installs v1.0.0 PHP + WP 4.4+ Updated Dec 30, 2022
automatemanagementmultisite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Manage Inactive Subsites Safe to Use in 2026?

Generally Safe

Score 85/100

Manage Inactive Subsites has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'manage-inactive-subsites' plugin v1.0.0 demonstrates a strong initial security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, or shortcodes, and all code signals related to dangerous functions, SQL queries, output escaping, file operations, and external HTTP requests are clean. Specifically, the complete absence of SQL queries not using prepared statements and the 100% proper output escaping are excellent indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerability history, including CVEs, which suggests a history of responsible development and patching.

However, the analysis does highlight some areas for caution. The presence of one cron event without any explicit mention of its authentication or capability checks in the static analysis could represent a potential blind spot. While the attack surface is currently zero without authentication, cron events can sometimes be exploited if not properly secured, especially if they perform sensitive actions. The lack of nonce checks and capability checks across the board, while not directly tied to an exploit in this version's analysis, generally increases the potential for vulnerabilities to be introduced in future updates or if the plugin's functionality expands. The zero taint analysis is positive, but it's important to remember that taint analysis is not exhaustive and may not catch all potential issues.

In conclusion, 'manage-inactive-subsites' v1.0.0 presents a very low-risk profile due to its clean static analysis results and lack of vulnerability history. The developers appear to follow good practices regarding SQL and output handling. The primary weakness, albeit minor given the current state, lies in the potential for the cron event to be a future entry point if not secured. Continued vigilance and robust testing of any future updates will be crucial.

Key Concerns

  • Cron event without explicit auth/capability checks
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Manage Inactive Subsites Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Manage Inactive Subsites Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Manage Inactive Subsites Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Manage Inactive Subsites Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionplugins_loadedmanage-inactive-subsites.php:46

Scheduled Events 1

manage_inactive_subsites_cron_hourly
Maintenance & Trust

Manage Inactive Subsites Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 30, 2022
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Manage Inactive Subsites Developer Profile

Marcin Pietrzak

23 plugins · 89K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
274 days
View full developer profile
Detection Fingerprints

How We Detect Manage Inactive Subsites

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Manage Inactive Subsites