Mu Manager – Manage mu-plugins like standard plugins Security & Risk Analysis

wordpress.org/plugins/mu-manager

It lets you disable, enable, and delete mu-plugins as you do with the standard plugins.

700 active installs v0.0.3 PHP 5.6+ WP 4.6+ Updated Dec 5, 2025
mu-pluginmust-use
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mu Manager – Manage mu-plugins like standard plugins Safe to Use in 2026?

Generally Safe

Score 100/100

Mu Manager – Manage mu-plugins like standard plugins has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "mu-manager" plugin v0.0.3 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals are overwhelmingly positive, with no dangerous functions, all SQL queries using prepared statements, and 100% of output properly escaped. The presence of nonce checks and capability checks further demonstrates a commitment to secure coding practices. The plugin also reports no known vulnerabilities or CVEs, historical or current, which is a very positive indicator.

While the static analysis reveals no immediate critical risks, the taint analysis shows zero flows analyzed, which means we cannot definitively rule out the possibility of subtle vulnerabilities that static analysis alone might miss. The presence of file operations, though not explicitly flagged as a risk without further context, warrants a cautious approach. The overall lack of attack vectors and strong security controls, combined with a clean vulnerability history, suggests a plugin that has been developed with security in mind. However, the limited scope of the taint analysis prevents a complete assessment of potential hidden risks. For a truly robust security assessment, deeper dynamic analysis or manual code review would be beneficial.

Vulnerabilities
None known

Mu Manager – Manage mu-plugins like standard plugins Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mu Manager – Manage mu-plugins like standard plugins Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
33 escaped
Nonce Checks
3
Capability Checks
7
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped33 total outputs
Attack Surface

Mu Manager – Manage mu-plugins like standard plugins Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initadmin\mupm-admin.php:6
filterplugin_action_linksadmin\mupm-admin.php:31
actionafter_plugin_rowadmin\mupm-admin.php:67
actionin_admin_headeradmin\mupm-admin.php:143
filterplugins_listadmin\mupm-helper.php:108
Maintenance & Trust

Mu Manager – Manage mu-plugins like standard plugins Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 5, 2025
PHP min version5.6
Downloads8K

Community Trust

Rating100/100
Number of ratings7
Active installs700
Developer Profile

Mu Manager – Manage mu-plugins like standard plugins Developer Profile

Jose Mortellaro

56 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
62 days
View full developer profile
Detection Fingerprints

How We Detect Mu Manager – Manage mu-plugins like standard plugins

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/mu-manager/admin/mupm-admin.php

HTML / DOM Fingerprints

CSS Classes
inactiveis-uninstallable
HTML Comments
<!-- Load backend scripts only in the mu-plugins page. --><!-- Add action links to the mu-plugins. --><!-- Add disabled mu-plugins after the active mu-plugins. -->
Data Attributes
aria-labeldata-title
JS Globals
eos_mupm_init
FAQ

Frequently Asked Questions about Mu Manager – Manage mu-plugins like standard plugins