
Remove "Powered by WordPress" Security & Risk Analysis
wordpress.org/plugins/remove-powered-by-wpRemoves the WordPress credit on all default WordPress themes and replaces with a widget sidebar for those wanting to customise the theme.
Is Remove "Powered by WordPress" Safe to Use in 2026?
Generally Safe
Score 100/100Remove "Powered by WordPress" has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "remove-powered-by-wp" plugin version 1.6.2 exhibits a generally good security posture, with strong adherence to several secure coding practices. The absence of dangerous functions, SQL injection vulnerabilities (100% prepared statements), and file operations is a significant strength. Furthermore, the plugin demonstrates excellent output escaping with 98% of outputs properly handled, and it has no recorded vulnerabilities or CVEs, indicating a history of responsible development.
However, a notable concern arises from the plugin's attack surface. It possesses one AJAX handler that lacks authentication checks. While the taint analysis shows no detected vulnerabilities, an unprotected entry point, especially an AJAX handler, can still be a vector for abuse if an attacker can trigger it. The presence of a single nonce check is a positive, but it doesn't cover the identified unprotected AJAX handler. This single unprotected entry point, despite the otherwise clean code, represents the most significant risk.
In conclusion, the plugin is well-developed with a strong emphasis on preventing common vulnerabilities like SQL injection and XSS. The lack of historical issues is reassuring. The primary weakness is the unprotected AJAX endpoint, which should be addressed to fully secure the plugin. Overall, the strengths outweigh the weaknesses, but the unprotected entry point warrants attention.
Key Concerns
- AJAX handler without auth check
Remove "Powered by WordPress" Security Vulnerabilities
Remove "Powered by WordPress" Release Timeline
Remove "Powered by WordPress" Code Analysis
Output Escaping
Remove "Powered by WordPress" Attack Surface
AJAX Handlers 1
WordPress Hooks 27
Maintenance & Trust
Remove "Powered by WordPress" Maintenance & Trust
Maintenance Signals
Community Trust
Remove "Powered by WordPress" Alternatives
Options for Twenty Twenty-One
options-for-twenty-twenty-one
Adds powerful customizer options to modify all aspects of the default WordPress theme Twenty Twenty-One.
Options for Twenty Seventeen
options-for-twenty-seventeen
Adds powerful customizer options to modify all aspects of the default WordPress theme Twenty Seventeen.
Options for Twenty Twenty
options-for-twenty-twenty
Adds powerful customizer options to modify all aspects of the default WordPress theme Twenty Twenty.
Customize Twenty Seventeen
customize-twenty-seventeen
Customize Twenty Seventeen theme - add Google Fonts, use new templates and get other options to easily customize your site.
Options for Twenty Nineteen
options-for-twenty-nineteen
Adds powerful customizer options to modify all aspects of the default WordPress theme Twenty Nineteen.
Remove "Powered by WordPress" Developer Profile
12 plugins · 43K total installs
How We Detect Remove "Powered by WordPress"
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.