
WP Pages Only Security & Risk Analysis
wordpress.org/plugins/pages-onlyThis plugin simply changes the default "Write" and "Manage" links in admin to go to pages instead of posts.
Is WP Pages Only Safe to Use in 2026?
Generally Safe
Score 85/100WP Pages Only has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pages-only" v1.0 plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or taint flows with unsanitized paths is a significant strength. Furthermore, the plugin demonstrates a complete lack of known CVEs, indicating a history of secure development or prompt patching. The total absence of entry points like AJAX handlers, REST API routes, shortcodes, and cron events suggests a very limited attack surface, further bolstering its security.
However, it's important to note the complete lack of capability checks and nonce checks, while not directly indicative of a vulnerability in this specific version due to the absence of user-facing entry points, represents a potential future risk. If the plugin were to be extended or modified to include such entry points, these missing checks would become critical security concerns. The current assessment is heavily influenced by the plugin's minimal functionality, which inherently reduces its attack surface. While the plugin is secure as presented, its lack of user interaction points means its real-world impact and security implications are minimal.
In conclusion, the "pages-only" v1.0 plugin is highly secure in its current iteration, demonstrating excellent coding practices by avoiding common vulnerability patterns. Its vulnerability history is clean, and its static analysis reveals no immediate threats. The primary area for potential future concern lies in the proactive implementation of capability and nonce checks should its functionality evolve to include more interactive features.
Key Concerns
- No capability checks found
- No nonce checks found
WP Pages Only Security Vulnerabilities
WP Pages Only Release Timeline
WP Pages Only Code Analysis
WP Pages Only Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP Pages Only Maintenance & Trust
Maintenance Signals
Community Trust
WP Pages Only Alternatives
Exclude Pages
exclude-pages
This plugin adds a checkbox, “include this page in menus”, uncheck this to exclude pages from the page navigation that users see on your site.
Exclude Pages From Menu
exclude-pages-from-menu
The plugin provides option in the page edit screen to remove page from navigation menu in the front end of site.
Auto Submenu
auto-submenu
Dynamic menus: Add a page to your menu and then let WordPress automatically add the child pages.
Hide Drafts in Menus
hide-drafts-in-menus
Hide unpublished pages in your custom menus.
Page Management Dropdown
page-management-dropdown
Adds a link to edit each individual page to the Pages admin menu.
WP Pages Only Developer Profile
3 plugins · 30 total installs
How We Detect WP Pages Only
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.