
NHR Advanced Options Table Manager & Autoload Optimizer Security & Risk Analysis
wordpress.org/plugins/nhrrob-options-table-managerOptimize WordPress with Advanced Option History, Autoload Health Checks, and Automated Cleanup. Boost performance by reducing database bloat.
Is NHR Advanced Options Table Manager & Autoload Optimizer Safe to Use in 2026?
Generally Safe
Score 98/100NHR Advanced Options Table Manager & Autoload Optimizer has a strong security track record. Known vulnerabilities have been patched promptly.
The nhrrob-options-table-manager plugin exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to WordPress security best practices with 100% output escaping and a high percentage of SQL queries using prepared statements. The plugin also implements a substantial number of nonce and capability checks, indicating an awareness of securing entry points. However, the static analysis reveals significant concerns, particularly the presence of the 'unserialize' function, which is a known vector for deserialization vulnerabilities. While no current CVEs are unpatched, the historical presence of a high severity 'Deserialization of Untrusted Data' vulnerability, coupled with a recent past vulnerability, suggests a recurring risk in this area.
The taint analysis highlights 7 high-severity flows, which, when combined with the 'unserialize' function, strongly suggest potential deserialization vulnerabilities exploitable if untrusted data can reach these flows. The presence of 8 unsanitized paths further exacerbates this risk. Although the attack surface appears to be zero based on the provided entry point count, the internal code signals and historical vulnerability patterns point to underlying weaknesses that could be exploited through other means or if internal logic is bypassed.
In conclusion, while the plugin has strengths in output escaping and prepared statements, the identified use of 'unserialize', coupled with high-severity taint flows and a history of deserialization vulnerabilities, presents a notable risk. The absence of current unpatched CVEs is positive, but the recurring nature of the vulnerability type warrants vigilance and potential remediation efforts to address the underlying code patterns.
Key Concerns
- Presence of 'unserialize' function
- 7 high severity taint flows
- 8 unsanitized paths
- History of deserialization vulnerability
- Bundled library (DataTables)
NHR Advanced Options Table Manager & Autoload Optimizer Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
NHR Options Table Manager <= 1.1.2 - Authenticated (Admin+) PHP Object Injection
NHR Advanced Options Table Manager & Autoload Optimizer Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
NHR Advanced Options Table Manager & Autoload Optimizer Attack Surface
WordPress Hooks 7
Scheduled Events 2
Maintenance & Trust
NHR Advanced Options Table Manager & Autoload Optimizer Maintenance & Trust
Maintenance Signals
Community Trust
NHR Advanced Options Table Manager & Autoload Optimizer Alternatives
Delete Expired Transients
delete-expired-transients
Delete old, expired transients from WordPress wp_options table
atec Database
atec-database
Manage, clean, and optimize your WordPress database with detailed control over tables and options.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Imagify Image Optimization – Optimize Images | Compress Images | Convert WebP | Convert AVIF
imagify
Optimize images in 1-click: compress images, convert to WebP & AVIF, resize, and boost your site with the easiest WordPress image optimization plugin!
WP Fastest Cache – WordPress Cache Plugin
wp-fastest-cache
The simplest and fastest WP Cache system
NHR Advanced Options Table Manager & Autoload Optimizer Developer Profile
4 plugins · 180 total installs
How We Detect NHR Advanced Options Table Manager & Autoload Optimizer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nhrrob-options-table-manager/assets/js/admin.js/wp-content/plugins/nhrrob-options-table-manager/assets/js/dataTables.min.js/wp-content/plugins/nhrrob-options-table-manager/assets/css/admin.css/wp-content/plugins/nhrrob-options-table-manager/assets/css/dataTables.dataTables.cssnhrrob-options-table-manager/assets/js/admin.js?ver=nhrrob-options-table-manager/assets/js/dataTables.min.js?ver=2.1.8nhrrob-options-table-manager/assets/css/admin.css?ver=nhrrob-options-table-manager/assets/css/dataTables.dataTables.css?ver=HTML / DOM Fingerprints
nhrotm_ajax_object