
Prevent Users From Deleting Post and Pages Security & Risk Analysis
wordpress.org/plugins/prevent-users-from-deleting-pages-posts-custom-post-typesThis plugin prevents users from deleting pages, posts and custom post types.
Is Prevent Users From Deleting Post and Pages Safe to Use in 2026?
Generally Safe
Score 85/100Prevent Users From Deleting Post and Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'prevent-users-from-deleting-pages-posts-custom-post-types' v0.3 demonstrates a strong adherence to several security best practices. The static analysis reveals a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. This significantly reduces the potential entry points for attackers. Furthermore, all observed SQL queries utilize prepared statements, mitigating the risk of SQL injection vulnerabilities. The plugin also correctly uses capability checks for its operations.
However, a significant concern arises from the complete lack of output escaping. With 15 total outputs analyzed and 0% properly escaped, this creates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-controlled data that is then displayed on the site. The absence of nonce checks on any entry points, while the attack surface is zero, would be a concern if the attack surface were larger.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the generally good code practices observed, suggests a developer who is aware of security. Despite this positive history, the critical flaw in output escaping cannot be overlooked. In conclusion, while the plugin has a solid foundation in terms of attack surface and SQL security, the unescaped output presents a serious security risk that needs immediate attention.
Key Concerns
- 0% of outputs properly escaped
- No nonce checks found
Prevent Users From Deleting Post and Pages Security Vulnerabilities
Prevent Users From Deleting Post and Pages Release Timeline
Prevent Users From Deleting Post and Pages Code Analysis
Output Escaping
Prevent Users From Deleting Post and Pages Attack Surface
WordPress Hooks 6
Maintenance & Trust
Prevent Users From Deleting Post and Pages Maintenance & Trust
Maintenance Signals
Community Trust
Prevent Users From Deleting Post and Pages Alternatives
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Comment Cleaner — Bulk Delete & Disable Comments
delete-all-comments-of-website
Delete, export, import, and manage WordPress comments with bulk tools and comment-control settings.
Disable Comments & Delete All Comments
comments-plus
Disable comments globally on all posts or certain post types. Delete all comments at once, by post type or comment status. Manage links in comments.
Disable User Login
disable-user-login
Disable user accounts without deleting them. One-click enable/disable, bulk actions, force logout, and customizable disabled message.
Remove Author Pages
remove-author-pages
Remove author pages and link authors to home page
Prevent Users From Deleting Post and Pages Developer Profile
3 plugins · 50 total installs
How We Detect Prevent Users From Deleting Post and Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
admin_disable_noticeselect_allunselect_alljQuery$