Remove WP version everywhere Security & Risk Analysis

wordpress.org/plugins/remove-wp-version-everywhere

Removes WordPress version from RSS, posts and pages supports network activation.

300 active installs v1.0.1 PHP + WP 2.5+ Updated May 5, 2021
remove-generatedremove-versionremove-version-rssremove-wordpress-versionversion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Remove WP version everywhere Safe to Use in 2026?

Generally Safe

Score 85/100

Remove WP version everywhere has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "remove-wp-version-everywhere" plugin, in version 1.0.1, exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries, or file operations is a significant positive indicator. Furthermore, the complete lack of identified taint flows, meaning no user-supplied data can reach sensitive functions without proper sanitization, is excellent. The plugin also demonstrates good practice by not making external HTTP requests and having no identifiable attack surface components like AJAX handlers, REST API routes, or shortcodes that are unprotected. This suggests the plugin is designed with security in mind, focusing on its core functionality without introducing common vulnerabilities.

The vulnerability history is also a major strength, showing no known CVEs, either historical or currently unpatched. This, combined with the clean static analysis, indicates a low risk of exploitation for known vulnerabilities. The plugin appears to be mature and has not been a target for significant security flaws. However, it's important to note that the "0 Nonce checks" and "0 Capability checks" are listed. While the plugin's minimal attack surface might make this less critical in practice for this specific plugin, in general, relying solely on the absence of an attack surface for security is not a robust strategy. For a plugin whose primary function is to modify core WordPress behavior (even if minor), some form of internal checks or contextual validation might be considered a good practice for future iterations to further harden it.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Remove WP version everywhere Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Remove WP version everywhere Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Remove WP version everywhere Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterthe_generatorremver.php:57
Maintenance & Trust

Remove WP version everywhere Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 5, 2021
PHP min version
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

Remove WP version everywhere Developer Profile

frisno

1 plugin · 300 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Remove WP version everywhere

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Generator Patterns
wp-content/plugins/remove-wp-version-everywhere/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Remove WP version everywhere