Remove WP version and shortlink Security & Risk Analysis

wordpress.org/plugins/remove-wp-version-and-shortlink

Removes WordPress version number , shortlink, wlwmanifest and RSD

300 active installs v1.0 PHP + WP 2.5+ Updated May 1, 2013
remove-shortlinkremove-versionremove-wordpress-versionremovesversion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Remove WP version and shortlink Safe to Use in 2026?

Generally Safe

Score 85/100

Remove WP version and shortlink has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "remove-wp-version-and-shortlink" plugin version 1.0 exhibits a strong security posture for its current version and scope. The code analysis reveals no dangerous functions, no SQL queries, and all potential outputs are properly escaped, which are excellent security practices. Furthermore, the complete absence of identifiable entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. The lack of any recorded vulnerabilities, including CVEs, further reinforces this positive assessment.

However, the analysis also highlights a complete lack of security checks, including nonce and capability checks. While the current lack of entry points mitigates the immediate risk, this absence of security controls could become a significant concern if the plugin were to be expanded in the future to include any user-facing functionality or data handling. The plugin's current design, while secure by obscurity due to its minimal functionality, does not actively implement robust security measures that would protect against more sophisticated or future threats. The strength lies in its limited scope, but the weakness is the lack of built-in security safeguards.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Remove WP version and shortlink Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Remove WP version and shortlink Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Remove WP version and shortlink Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Remove WP version and shortlink Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedMay 1, 2013
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

Remove WP version and shortlink Developer Profile

naganandhini

1 plugin · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Remove WP version and shortlink

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Remove WP version and shortlink