Remove @User Autocomplete from Block Editor Security & Risk Analysis

wordpress.org/plugins/remove-user-autocomplete-from-block-editor

Removes the @user autocomplete feature from the block editor. By default on Gutenberg, when you type @, the block editor performs a search through the …

10 active installs v0.1 PHP 5.6+ WP 5.8+ Updated Nov 27, 2025
autocompleteeditorremoveuser
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Remove @User Autocomplete from Block Editor Safe to Use in 2026?

Generally Safe

Score 100/100

Remove @User Autocomplete from Block Editor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "remove-user-autocomplete-from-block-editor" plugin v0.1 exhibits a very strong security posture based on the provided static analysis and vulnerability history. The static analysis reveals an absence of known attack surfaces such as AJAX handlers, REST API routes, or shortcodes, and critically, all identified code signals indicate adherence to secure coding practices. There are no dangerous functions, SQL queries are 100% prepared, all output is properly escaped, and there are no file operations or external HTTP requests. Furthermore, the lack of nonce and capability checks in the static analysis, when combined with the absence of any entry points, suggests that these checks are not necessary for the plugin's intended functionality and therefore not a security weakness in this context.

The vulnerability history is equally positive, with zero known CVEs recorded. This indicates a history of responsible development and a lack of previously exploited vulnerabilities. The absence of any common vulnerability types further reinforces this. While the plugin has a very limited scope and functionality (implied by the lack of complex code signals and attack surface), this can also be a strength in security as it reduces the potential for vulnerabilities. The strengths of this plugin lie in its clean code, adherence to best practices, and unblemished vulnerability history. There are no identifiable weaknesses based on the provided data.

Vulnerabilities
None known

Remove @User Autocomplete from Block Editor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Remove @User Autocomplete from Block Editor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Remove @User Autocomplete from Block Editor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterenqueue_block_editor_assetsremove-user-autocomplete-from-block-editor.php:27
Maintenance & Trust

Remove @User Autocomplete from Block Editor Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 27, 2025
PHP min version5.6
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Remove @User Autocomplete from Block Editor Developer Profile

Jb Audras

24 plugins · 64K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
661 days
View full developer profile
Detection Fingerprints

How We Detect Remove @User Autocomplete from Block Editor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/remove-user-autocomplete-from-block-editor/remove-user-autocomplete-from-block-editor.js
Script Paths
/wp-content/plugins/remove-user-autocomplete-from-block-editor/remove-user-autocomplete-from-block-editor.js

HTML / DOM Fingerprints

JS Globals
wp.blocks.unregisterBlockHookwp.blocks.registerBlockTypewp.editor.useSelect
FAQ

Frequently Asked Questions about Remove @User Autocomplete from Block Editor