
Remove WP version everywhere Security & Risk Analysis
wordpress.org/plugins/remove-wp-version-everywhereRemoves WordPress version from RSS, posts and pages supports network activation.
Is Remove WP version everywhere Safe to Use in 2026?
Generally Safe
Score 85/100Remove WP version everywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "remove-wp-version-everywhere" plugin, in version 1.0.1, exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries, or file operations is a significant positive indicator. Furthermore, the complete lack of identified taint flows, meaning no user-supplied data can reach sensitive functions without proper sanitization, is excellent. The plugin also demonstrates good practice by not making external HTTP requests and having no identifiable attack surface components like AJAX handlers, REST API routes, or shortcodes that are unprotected. This suggests the plugin is designed with security in mind, focusing on its core functionality without introducing common vulnerabilities.
The vulnerability history is also a major strength, showing no known CVEs, either historical or currently unpatched. This, combined with the clean static analysis, indicates a low risk of exploitation for known vulnerabilities. The plugin appears to be mature and has not been a target for significant security flaws. However, it's important to note that the "0 Nonce checks" and "0 Capability checks" are listed. While the plugin's minimal attack surface might make this less critical in practice for this specific plugin, in general, relying solely on the absence of an attack surface for security is not a robust strategy. For a plugin whose primary function is to modify core WordPress behavior (even if minor), some form of internal checks or contextual validation might be considered a good practice for future iterations to further harden it.
Key Concerns
- No capability checks found
- No nonce checks found
Remove WP version everywhere Security Vulnerabilities
Remove WP version everywhere Code Analysis
Remove WP version everywhere Attack Surface
WordPress Hooks 1
Maintenance & Trust
Remove WP version everywhere Maintenance & Trust
Maintenance Signals
Community Trust
Remove WP version everywhere Alternatives
Remove WP version and shortlink
remove-wp-version-and-shortlink
Removes WordPress version number , shortlink, wlwmanifest and RSD
Remove Version Info
remove-version-info
Remove the version from your WordPress website completely, increasing security and thwarting potential hacks by hiding WordPress version information f …
No Version Tags
remove-code-version-tags
Description: Upon activation, this plugin will automatically eliminate the annoying '?ver=x.x' signs from your perfect code :)
WP Version in Query String Modifier
wp-version-in-query-string-modifier
Removes or modifies the version (query string 'ver' parameter) in media resources' url.
AB WP Security
ab-wp-security
Security plugin that stops User Enumeration in WordPress, removes WordPress Version Number, disable directory browsing and Disable XML-RPC
Remove WP version everywhere Developer Profile
1 plugin · 300 total installs
How We Detect Remove WP version everywhere
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
wp-content/plugins/remove-wp-version-everywhere/