PlugeGuard – Hidden Login Detector Security & Risk Analysis

wordpress.org/plugins/plugeguard

Scans your WordPress installation for hardcoded login credentials (usernames/passwords) and allows safe removal from PHP files.

0 active installs v1.1 PHP 8.0+ WP 5.6+ Updated Sep 16, 2025
firewallhidden-login-scannerremove-hidden-passwordsscannersecurity
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PlugeGuard – Hidden Login Detector Safe to Use in 2026?

Generally Safe

Score 100/100

PlugeGuard – Hidden Login Detector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The 'plugeguard' v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs and a clean vulnerability history are significant strengths, indicating a mature and well-maintained plugin. The code analysis reveals a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, which is a highly positive sign. Furthermore, the plugin demonstrates good practices in database interaction with 100% of SQL queries using prepared statements and includes a reasonable number of nonce and capability checks.

Key Concerns

  • Output escaping is not fully implemented
Vulnerabilities
None known

PlugeGuard – Hidden Login Detector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PlugeGuard – Hidden Login Detector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
15 escaped
Nonce Checks
3
Capability Checks
2
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

65% escaped23 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
remove_code (plugeguard.php:202)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

PlugeGuard – Hidden Login Detector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuplugeguard.php:34
actionadmin_post_plugeguard_remove_codeplugeguard.php:35
actionadmin_post_plugeguard_update_fileplugeguard.php:36
actionadmin_enqueue_scriptsplugeguard.php:37
actionadmin_initplugeguard.php:38
Maintenance & Trust

PlugeGuard – Hidden Login Detector Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 16, 2025
PHP min version8.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PlugeGuard – Hidden Login Detector Developer Profile

Maruf Hossain

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PlugeGuard – Hidden Login Detector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/plugeguard/assets/css/plugeguard.css/wp-content/plugins/plugeguard/assets/js/plugeguard.js/wp-content/plugins/plugeguard/assets/js/plugeguard-editor.js
Script Paths
/wp-content/plugins/plugeguard/assets/js/plugeguard.js/wp-content/plugins/plugeguard/assets/js/plugeguard-editor.js
Version Parameters
plugeguard.css?ver=plugeguard.js?ver=plugeguard-editor.js?ver=

HTML / DOM Fingerprints

CSS Classes
plugeguard-remove-button
Data Attributes
data-plugeguard
JS Globals
plugeguard_data
FAQ

Frequently Asked Questions about PlugeGuard – Hidden Login Detector