
Plugins Page Tweaker Security & Risk Analysis
wordpress.org/plugins/plugins-managerThe plugin adds icons on the plugins page and other tweaks, such as displaying the GIT branch
Is Plugins Page Tweaker Safe to Use in 2026?
Generally Safe
Score 92/100Plugins Page Tweaker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "plugins-manager" v1.4.5 plugin presents a generally positive security posture based on the static analysis. The absence of identified CVEs and a clean vulnerability history is a strong indicator of good development practices. Furthermore, the lack of unprotected entry points, such as AJAX handlers, REST API routes, shortcodes, and cron events, significantly limits the potential attack surface. The code also demonstrates a commitment to secure SQL handling by using prepared statements exclusively and includes nonce and capability checks, which are crucial for preventing common web vulnerabilities.
However, a notable concern arises from the output escaping. With 18 outputs analyzed and only 17% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This means that user-supplied data, if not handled carefully, could be injected into the output and executed by a user's browser. Additionally, the taint analysis revealed one flow with unsanitized paths, which, while not classified as critical or high severity in this analysis, still warrants attention as it could potentially lead to path traversal or other file system related vulnerabilities if not properly mitigated.
In conclusion, while the plugin has strengths in its limited attack surface and secure SQL practices, the significant lack of output escaping and the presence of an unsanitized path flow are key areas of weakness. The lack of historical vulnerabilities is encouraging, but the current code analysis reveals immediate risks that need to be addressed to ensure a more robust security profile.
Key Concerns
- Poor output escaping (17% properly escaped)
- Flows with unsanitized paths (1)
Plugins Page Tweaker Security Vulnerabilities
Plugins Page Tweaker Code Analysis
Output Escaping
Data Flow Analysis
Plugins Page Tweaker Attack Surface
WordPress Hooks 24
Maintenance & Trust
Plugins Page Tweaker Maintenance & Trust
Maintenance Signals
Community Trust
Plugins Page Tweaker Alternatives
Easy Digital Downloads – Variable Pricing Descriptions
edd-variable-pricing-descriptions
Provide detailed descriptions to customers for your variations when using variable prices with Easy Digital Downloads.
Manage Customized Plugin Updates
manage-customized-plugin-updates
Are you a web developer or website design company who has installed / customized plugins for your clients and you're having a hard time managing …
Admin Menu Cleaner
wp-admin-menu-wizard
Wp Admin Menu Wizard lets you hide the menu items you do not use very often.
Checkout Styler for Easy Digital Downloads
checkout-styler-for-easy-digital-downloads
An addon for Easy Digital Downloads plugin to help you customize the checkout page with Live Preview.
Easy Digital Downloads – Slack Notifications
easy-digital-downloads-slack-notifications
This plugin send a notification to your Slack channel whenever a sale occurs on your Easy Digital Downloads store.
Plugins Page Tweaker Developer Profile
3 plugins · 180 total installs
How We Detect Plugins Page Tweaker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plugins-manager/admin/assets/css/wtbp-admin.css/wp-content/plugins/plugins-manager/admin/assets/js/wtbp-admin.js/wp-content/plugins/plugins-manager/admin/assets/js/wtbp-admin.jsplugins-manager/admin/assets/css/wtbp-admin.css?ver=plugins-manager/admin/assets/js/wtbp-admin.js?ver=HTML / DOM Fingerprints
wtbp-git-versionwtbp-git-iconwtbp-git-version-branchdata-wtbp-actiondata-wtbp-bulk-action-titlewindow.WTBP_ AJAX_URLwindow.WTBP_PLUGIN_URL