Meks Quick Plugin Disabler Security & Risk Analysis

wordpress.org/plugins/meks-quick-plugin-disabler

Temporarily disable (and restore) all currently active plugins with a single click

2K active installs v1.0 PHP + WP 3.7+ Updated Jul 29, 2024
activatedeactivatedebugdisableplugins
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEDec 15, 2025
Safety Verdict

Is Meks Quick Plugin Disabler Safe to Use in 2026?

Mostly Safe

Score 70/100

Meks Quick Plugin Disabler is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Dec 15, 2025Updated 1yr ago
Risk Assessment

The meks-quick-plugin-disabler v1.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no dangerous functions, no raw SQL queries, and no external HTTP requests, which are all good indicators of secure coding practices. However, a significant concern is the lack of nonce and capability checks across all entry points. This, combined with a medium severity Cross-Site Request Forgery (CSRF) vulnerability in its history that remains unpatched, suggests potential weaknesses in authentication and authorization mechanisms. The plugin's history indicates a past vulnerability that has not been addressed, which is a serious red flag for ongoing security.

While the code analysis shows a lack of obvious vulnerabilities like SQL injection or XSS due to prepared statements and some output escaping, the absence of proper nonce and capability checks is a critical oversight. This means that an attacker could potentially trigger plugin actions without proper user authorization. The single medium severity CSRF vulnerability, even if dated, is still a known issue that exposes users to risk. The plugin's strength lies in its minimal attack surface and use of prepared statements, but its weakness is the clear disregard for proper authorization checks, which, combined with historical vulnerabilities, points to a moderate to high-risk plugin that requires immediate attention to patch the known CVE.

Key Concerns

  • Unpatched medium severity CVE
  • No nonce checks on entry points
  • No capability checks on entry points
  • 50% of outputs not properly escaped
Vulnerabilities
1 published

Meks Quick Plugin Disabler Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68083medium · 4.3Cross-Site Request Forgery (CSRF)

Meks Quick Plugin Disabler <= 1.0 - Cross-Site Request Forgery

Dec 15, 2025Unpatched
Version History

Meks Quick Plugin Disabler Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Meks Quick Plugin Disabler Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

Meks Quick Plugin Disabler Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedmeks-quick-plugin-disabler.php:41
actionadmin_initmeks-quick-plugin-disabler.php:44
actionpre_current_active_pluginsmeks-quick-plugin-disabler.php:47
actionadmin_noticesmeks-quick-plugin-disabler.php:95
actionadmin_noticesmeks-quick-plugin-disabler.php:105
Maintenance & Trust

Meks Quick Plugin Disabler Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 29, 2024
PHP min version
Downloads19K

Community Trust

Rating100/100
Number of ratings7
Active installs2K
Developer Profile

Meks Quick Plugin Disabler Developer Profile

Meks

14 plugins · 117K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Meks Quick Plugin Disabler

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<a href=" Temporarily disable all active plugins Restore disabled plugins
FAQ

Frequently Asked Questions about Meks Quick Plugin Disabler