Orbisius Blank Slate Security & Risk Analysis

wordpress.org/plugins/orbisius-blank-slate

This plugin allows you to delete content from your WordPress site/blog.

10 active installs v1.0.1 PHP + WP 2.6+ Updated May 11, 2013
admindeleteresetwordpress-reset
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Orbisius Blank Slate Safe to Use in 2026?

Generally Safe

Score 85/100

Orbisius Blank Slate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'orbisius-blank-slate' v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant positive. Furthermore, the lack of dangerous functions, SQL queries using prepared statements, file operations, and external HTTP requests are all excellent security practices. The presence of a nonce check, albeit only one, is also a good sign. However, a major concern arises from the complete absence of output escaping (0% properly escaped). This represents a significant risk, as unsanitized output can lead to cross-site scripting (XSS) vulnerabilities. While the taint analysis shows no identified unsanitized flows, the lack of output escaping provides a direct path for attackers to inject malicious scripts if any user-controlled data is ever displayed without sanitization.

The vulnerability history of this plugin is clean, with no recorded CVEs. This, combined with the positive static analysis signals, suggests a plugin that has historically been developed with security in mind, or at least has not had publicly disclosed vulnerabilities. The strengths lie in its minimal attack surface and adherence to secure coding practices regarding SQL and external requests. The primary weakness, and a critical one, is the complete failure in output escaping, which presents a substantial risk that needs immediate attention. A balanced conclusion is that while the plugin avoids many common pitfalls, the unescaped output is a critical oversight that severely compromises its overall security.

Key Concerns

  • All output is unescaped
Vulnerabilities
None known

Orbisius Blank Slate Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Orbisius Blank Slate Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
42
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped42 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
orbisius_blank_slate_tools_action (orbisius-blank-slate.php:78)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Orbisius Blank Slate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initorbisius-blank-slate.php:29
actionadmin_menuorbisius-blank-slate.php:30
actionwp_footerorbisius-blank-slate.php:31
filterplugin_action_linksorbisius-blank-slate.php:55
Maintenance & Trust

Orbisius Blank Slate Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedMay 11, 2013
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Orbisius Blank Slate Developer Profile

Svetoslav Marinov

26 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
722 days
View full developer profile
Detection Fingerprints

How We Detect Orbisius Blank Slate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orbisius-blank-slate/assets/main.css
Version Parameters
orbisius-blank-slate/assets/main.css?ver=

HTML / DOM Fingerprints

CSS Classes
orbisius-blank-slate-containerapp-centerapp-button-containerapp-alert-errorapp-step-headingapp-button-negative
HTML Comments
MAILCHIMP SUBSCRIBE CODEMAILCHIMP SUBSCRIBE CODE
Data Attributes
orbisius_blank_slate_nonce
FAQ

Frequently Asked Questions about Orbisius Blank Slate