
Meks Quick Plugin Disabler Security & Risk Analysis
wordpress.org/plugins/meks-quick-plugin-disablerTemporarily disable (and restore) all currently active plugins with a single click
Is Meks Quick Plugin Disabler Safe to Use in 2026?
Mostly Safe
Score 70/100Meks Quick Plugin Disabler is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The meks-quick-plugin-disabler v1.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no dangerous functions, no raw SQL queries, and no external HTTP requests, which are all good indicators of secure coding practices. However, a significant concern is the lack of nonce and capability checks across all entry points. This, combined with a medium severity Cross-Site Request Forgery (CSRF) vulnerability in its history that remains unpatched, suggests potential weaknesses in authentication and authorization mechanisms. The plugin's history indicates a past vulnerability that has not been addressed, which is a serious red flag for ongoing security.
While the code analysis shows a lack of obvious vulnerabilities like SQL injection or XSS due to prepared statements and some output escaping, the absence of proper nonce and capability checks is a critical oversight. This means that an attacker could potentially trigger plugin actions without proper user authorization. The single medium severity CSRF vulnerability, even if dated, is still a known issue that exposes users to risk. The plugin's strength lies in its minimal attack surface and use of prepared statements, but its weakness is the clear disregard for proper authorization checks, which, combined with historical vulnerabilities, points to a moderate to high-risk plugin that requires immediate attention to patch the known CVE.
Key Concerns
- Unpatched medium severity CVE
- No nonce checks on entry points
- No capability checks on entry points
- 50% of outputs not properly escaped
Meks Quick Plugin Disabler Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Meks Quick Plugin Disabler <= 1.0 - Cross-Site Request Forgery
Meks Quick Plugin Disabler Release Timeline
Meks Quick Plugin Disabler Code Analysis
Output Escaping
Meks Quick Plugin Disabler Attack Surface
WordPress Hooks 5
Maintenance & Trust
Meks Quick Plugin Disabler Maintenance & Trust
Maintenance Signals
Community Trust
Meks Quick Plugin Disabler Alternatives
Quick Disabler
quick-disabler
Easily disable all active plugins—except this one—with one click. Re-enable them anytime using AJAX. Perfect for debugging and troubleshooting.
Plugin Load Filter
plugin-load-filter
Dynamically activate the selected plugins for each page. Response will be faster by filtering plugins.
Plugin Logic
plugin-logic
Url based plugin deactivation or activation.
FDP Debug
fdp-debug
It adds an action button to collect information to debug Freesoul Deactivate Plugins. If you don't use Freesoul Deactivate Plugins you don't …
User Blocker
user-blocker
To block users from admin side except admin users for specific day,time, and date or permanently.
Meks Quick Plugin Disabler Developer Profile
14 plugins · 117K total installs
How We Detect Meks Quick Plugin Disabler
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<a href=" Temporarily disable all active plugins Restore disabled plugins