
Ozh' Better Plugin Page Security & Risk Analysis
wordpress.org/plugins/ozh-better-plugin-pageAdds icons, quick action links, and less clutter to your plugin management page.
Is Ozh' Better Plugin Page Safe to Use in 2026?
Generally Safe
Score 85/100Ozh' Better Plugin Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'ozh-better-plugin-page' v1.4.2 plugin reveals a generally strong security posture. The plugin boasts zero detected entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, significantly limiting its attack surface. Furthermore, it exhibits a complete absence of dangerous functions and external HTTP requests. All detected SQL queries are properly prepared, and there are no identified taint flows, indicating a good effort to prevent common injection vulnerabilities.
However, a notable concern arises from the output escaping. With 2 total outputs and 0% properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic content rendered by this plugin could potentially be exploited if user-supplied data is not sanitized before being displayed. While the plugin includes one nonce check and no recorded vulnerability history, the lack of output escaping is a critical oversight that requires immediate attention. The absence of capability checks could also be a weakness if any sensitive operations were to be introduced in the future, although no such operations are apparent in this analysis.
In conclusion, 'ozh-better-plugin-page' v1.4.2 demonstrates good practices in minimizing its attack surface and handling database interactions securely. The absence of historical vulnerabilities is positive. The primary weakness, however, is the complete lack of output escaping, which presents a high risk of XSS vulnerabilities. This issue outweighs the otherwise positive findings and needs to be addressed to achieve a more robust security profile.
Key Concerns
- No output escaping detected
Ozh' Better Plugin Page Security Vulnerabilities
Ozh' Better Plugin Page Code Analysis
Output Escaping
Ozh' Better Plugin Page Attack Surface
WordPress Hooks 4
Maintenance & Trust
Ozh' Better Plugin Page Maintenance & Trust
Maintenance Signals
Community Trust
Ozh' Better Plugin Page Alternatives
Pluginer (formerly Instalist) – WP bulk plugin install & migrate
instalist
Create lists of your favourites plugins, export and import them in any new website to install all plugins in the list with just one single click.
Plugin Last Updated Warning
plugin-last-updated-warning
This plugin will display a warning for plugins that haven't received updates on the WP.org plugin repo the past year.
Enhanced Plugin Admin
enhanced-plugin-admin
At-a-glance diagnostic and security info displayed on your site's plugin page about the plugins you have installed (both active and inactive).
Multisite Usage Scanner
multisite-usage-scanner
Scan your WordPress multisite network to identify which plugins are actively used across sites. Helps admins safely clean up unused plugins.
Plugin Tags
plugin-tags
Add tags & filters to the plugins list to quickly & easily see what they do.
Ozh' Better Plugin Page Developer Profile
27 plugins · 5K total installs
How We Detect Ozh' Better Plugin Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ozh-better-plugin-page/plugin.css/wp-content/plugins/ozh-better-plugin-page/plugin.js/wp-content/plugins/ozh-better-plugin-page/jquery/jquery.tablesorter.min.js/wp-content/plugins/ozh-better-plugin-page/jquery/jquery.scrollTo.min.js/wp-content/plugins/ozh-better-plugin-page/plugin.js/wp-content/plugins/ozh-better-plugin-page/jquery/jquery.tablesorter.min.js/wp-content/plugins/ozh-better-plugin-page/jquery/jquery.scrollTo.min.jsozh-better-plugin-page/plugin.css?ver=ozh-better-plugin-page/plugin.js?ver=ozh-better-plugin-page/jquery/jquery.tablesorter.min.js?ver=ozh-better-plugin-page/jquery/jquery.scrollTo.min.js?ver=HTML / DOM Fingerprints
bpp_pluginbpp_upgbpp_wtf_msgbpp_wtf_msg_closeozh_bpp_nonce