
Never Let Me Go Security & Risk Analysis
wordpress.org/plugins/never-let-me-goIf someone wants to leave your WordPress, let them go.
Is Never Let Me Go Safe to Use in 2026?
Generally Safe
Score 92/100Never Let Me Go has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "never-let-me-go" v2.0.3 plugin exhibits a generally good security posture, with several positive indicators. The complete absence of dangerous functions, the consistent use of prepared statements for all SQL queries, and a high rate of output escaping (89%) are all strong signs of secure coding practices. Furthermore, the lack of any recorded vulnerabilities or CVEs in its history suggests a history of security-conscious development and maintenance.
However, there are specific areas of concern that elevate the risk profile. The plugin has one unprotected REST API route, which represents a direct entry point for potential attackers to interact with the plugin's functionality without proper authorization checks. While the attack surface is small overall, this single unprotected endpoint is a significant weakness. The presence of a file operation could also be a concern if not handled carefully, although no specific risks are detailed in the static analysis for this operation.
In conclusion, while the plugin benefits from a clean vulnerability history and strong defensive coding in areas like SQL and output handling, the unprotected REST API route introduces a notable risk that should be addressed. The overall security is good, but this specific flaw creates an exploitable weakness.
Key Concerns
- Unprotected REST API route
Never Let Me Go Security Vulnerabilities
Never Let Me Go Code Analysis
SQL Query Safety
Output Escaping
Never Let Me Go Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 22
Maintenance & Trust
Never Let Me Go Maintenance & Trust
Maintenance Signals
Community Trust
Never Let Me Go Alternatives
WP Frontend Delete Account
wp-frontend-delete-account
Lets customers delete their account by their own.
User Cleaner
ajdg-user-cleaner
If an account is registered and nothing is done with it the account is deleted after two weeks.
ByeUser – Self Service Account Deletion
byeuser-self-service-account-deletion
ByeUser - Self Service Account Deletion allows users to delete their own accounts via shortcode or profile page.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
custom-facebook-feed
Formerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
Never Let Me Go Developer Profile
14 plugins · 4K total installs
How We Detect Never Let Me Go
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/never-let-me-go/assets/css/admin.css/wp-content/plugins/never-let-me-go/assets/js/admin.js/wp-content/plugins/never-let-me-go/assets/js/admin.jsnever-let-me-go/assets/css/admin.css?ver=never-let-me-go/assets/js/admin.js?ver=HTML / DOM Fingerprints
data-confirm-labelNLMG/wp-json/nlmg/v1/settings[never-let-me-go-form]