Newer Not Better Security & Risk Analysis

wordpress.org/plugins/newer-not-better

Prevents selected plugins bugging you about updates

10 active installs v1.0.0 PHP 5.2+ WP 4.0.4+ Updated Oct 26, 2021
notificationspluginsupdates
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Newer Not Better Safe to Use in 2026?

Generally Safe

Score 85/100

Newer Not Better has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "newer-not-better" plugin v1.0.0 demonstrates a strong security posture based on the provided static analysis. There are no identified entry points with insufficient authentication or authorization checks, and the code signals indicate robust practices like 100% prepared statement usage for SQL queries and proper output escaping. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests significantly reduces the potential attack surface. The plugin's vulnerability history is clean, with zero recorded CVEs, suggesting a consistent track record of secure development or a lack of previous scrutiny that might have revealed issues. This plugin appears to be built with security in mind, prioritizing safe coding practices and minimizing exposure points.

However, the complete absence of any taint analysis flows, while seemingly positive, could also indicate that the static analysis tools were unable to effectively analyze the code for such vulnerabilities. This is a point of potential concern as it might mean that subtle or complex vulnerabilities were not detected. Additionally, the presence of capability checks without explicit information on what they protect raises a minor flag; while the checks exist, their effectiveness is not fully verifiable from the provided data alone. Overall, the plugin is in a good security state, but the lack of deep taint analysis findings warrants a cautious approach.

In conclusion, "newer-not-better" v1.0.0 exhibits excellent security hygiene with its minimal attack surface, secure coding practices for SQL and output, and clean vulnerability history. The static analysis results are overwhelmingly positive, pointing to a plugin that adheres to secure development principles. The only potential area for improvement or further investigation is the lack of detailed taint analysis findings, which could either signify a truly secure plugin or a limitation in the analysis process.

Key Concerns

  • No taint flows analyzed
  • Capability checks exist but context unknown
Vulnerabilities
None known

Newer Not Better Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Newer Not Better Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Newer Not Better Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterplugin_action_linksnewer-not-better.php:60
filtersite_transient_update_pluginsnewer-not-better.php:61
actionadmin_menunewer-not-better.php:62
actionadmin_initnewer-not-better.php:63
actionplugins_loadednewer-not-better.php:181
Maintenance & Trust

Newer Not Better Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedOct 26, 2021
PHP min version5.2
Downloads828

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Newer Not Better Developer Profile

Adam Ainsworth

4 plugins · 40 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Newer Not Better

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Newer Not Better