RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Security & Risk Analysis

wordpress.org/plugins/ris-version-switcher

Effortlessly switch between WordPress core and plugin versions for compatibility, troubleshooting, and testing.

70 active installs v1.0 PHP 7.4+ WP 5.0+ Updated Nov 21, 2024
update-managementversion-controlversion-switchwordpress-rollbackwordpress-version
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 22, 2025
Download
Safety Verdict

Is RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Safe to Use in 2026?

Mostly Safe

Score 70/100

RIS Version Switcher – Downgrade or Upgrade WP Versions Easily is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 1yr ago
Risk Assessment

The "ris-version-switcher" v1.0 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals that all identified entry points, including the four AJAX handlers, have capability checks, and there are no unescaped outputs or raw SQL queries. The absence of dangerous functions and unsanitized taint flows further suggests good coding practices in these areas. However, a significant concern arises from the complete lack of nonce checks on its AJAX handlers. This is a critical oversight that exposes the plugin to Cross-Site Request Forgery (CSRF) attacks, especially since the vulnerability history indicates a past CSRF vulnerability. The existence of a known, currently unpatched medium-severity CVE is a major red flag and demands immediate attention. While the code itself appears to be built with some security awareness, the unpatched vulnerability and the missing nonce protection significantly elevate the risk profile.

Key Concerns

  • Unpatched CVE exists
  • Missing nonce checks on AJAX handlers
Vulnerabilities
1 published

RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-57902medium · 4.3Cross-Site Request Forgery (CSRF)

RIS Version Switcher &#8211; Downgrade or Upgrade WP Versions Easily <= 1.0 - Cross-Site Request Forgery

Sep 22, 2025Unpatched
Version History

RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Release Timeline

v1.0Current1 CVE
Code Analysis
Analyzed Mar 16, 2026

RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
4
File Operations
13
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_risvs_fetch_plugin_versionsinc\ris-plugin.php:38
authwp_ajax_risvs_switcher_plugininc\ris-plugin.php:112
authwp_ajax_risvs_fetch_versionsinc\ris-wp-core.php:46
authwp_ajax_risvs_switcher_coreinc\ris-wp-core.php:190
WordPress Hooks 3
actioninitaction\init-functions.php:31
actionadmin_enqueue_scriptsaction\ris-enqueue.php:38
actionadmin_menuinc\ris-admin.php:29
Maintenance & Trust

RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 21, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

RIS Version Switcher – Downgrade or Upgrade WP Versions Easily Developer Profile

Md Taufiqur Rahman

1 plugin · 70 total installs

73
trust score
Avg Security Score
70/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RIS Version Switcher – Downgrade or Upgrade WP Versions Easily

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ris-version-switcher/assets/style.css/wp-content/plugins/ris-version-switcher/assets/script.js
Script Paths
/wp-content/plugins/ris-version-switcher/assets/script.js
Version Parameters
ris-version-switcher/assets/style.css?ver=ris-version-switcher/assets/script.js?ver=

HTML / DOM Fingerprints

JS Globals
risswitcherAjaxpluginData
FAQ

Frequently Asked Questions about RIS Version Switcher – Downgrade or Upgrade WP Versions Easily