
Never Let Me Go Security & Risk Analysis
wordpress.org/plugins/never-let-me-goIf someone wants to leave your WordPress, let them go.
Is Never Let Me Go Safe to Use in 2026?
Generally Safe
Score 92/100Never Let Me Go has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "never-let-me-go" v2.0.3 plugin exhibits a generally good security posture, with several positive indicators. The complete absence of dangerous functions, the consistent use of prepared statements for all SQL queries, and a high rate of output escaping (89%) are all strong signs of secure coding practices. Furthermore, the lack of any recorded vulnerabilities or CVEs in its history suggests a history of security-conscious development and maintenance.
However, there are specific areas of concern that elevate the risk profile. The plugin has one unprotected REST API route, which represents a direct entry point for potential attackers to interact with the plugin's functionality without proper authorization checks. While the attack surface is small overall, this single unprotected endpoint is a significant weakness. The presence of a file operation could also be a concern if not handled carefully, although no specific risks are detailed in the static analysis for this operation.
In conclusion, while the plugin benefits from a clean vulnerability history and strong defensive coding in areas like SQL and output handling, the unprotected REST API route introduces a notable risk that should be addressed. The overall security is good, but this specific flaw creates an exploitable weakness.
Key Concerns
- Unprotected REST API route
Never Let Me Go Security Vulnerabilities
Never Let Me Go Release Timeline
Never Let Me Go Code Analysis
SQL Query Safety
Output Escaping
Never Let Me Go Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 22
Maintenance & Trust
Never Let Me Go Maintenance & Trust
Maintenance Signals
Community Trust
Never Let Me Go Alternatives
WP Frontend Delete Account
wp-frontend-delete-account
Lets customers delete their account by their own.
User Cleaner
ajdg-user-cleaner
If an account is registered and nothing is done with it the account is deleted after two weeks.
Delete My Account for Ultimate Membership Pro
delete-my-account-addon-for-ultimate-membership-pro
Every user from Ultimate Membership Pro may delete their profile account with this extension activated
ByeUser – Self Service Account Deletion
byeuser-self-service-account-deletion
ByeUser - Self Service Account Deletion allows users to delete their own accounts via shortcode or profile page.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Never Let Me Go Developer Profile
14 plugins · 4K total installs
How We Detect Never Let Me Go
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/never-let-me-go/assets/css/admin.css/wp-content/plugins/never-let-me-go/assets/js/admin.js/wp-content/plugins/never-let-me-go/assets/js/admin.jsnever-let-me-go/assets/css/admin.css?ver=never-let-me-go/assets/js/admin.js?ver=HTML / DOM Fingerprints
data-confirm-labelNLMG/wp-json/nlmg/v1/settings[never-let-me-go-form]