
Roots Hide WP Security & Risk Analysis
wordpress.org/plugins/roots-hide-wpBen Word originally meant to "hide" the fact that you're using WordPress. There are currently a few things missing from this plugin tha …
Is Roots Hide WP Safe to Use in 2026?
Generally Safe
Score 85/100Roots Hide WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "roots-hide-wp" v0.1 plugin exhibits a seemingly strong security posture based on the provided static analysis. There is a complete absence of identified vulnerabilities in its history, and the code analysis indicates a healthy implementation with 100% proper output escaping and 100% prepared statements for SQL queries. Furthermore, there are no detected file operations or external HTTP requests, and the attack surface is reported as zero, with no unprotected entry points. This suggests a well-developed and secure plugin in terms of common web vulnerabilities.
However, one significant concern arises from the static analysis: the presence of the `create_function` dangerous function. While the taint analysis reports no unsanitized flows, the use of `create_function` is inherently risky as it can lead to arbitrary code execution if not handled with extreme care and proper sanitization, which is not explicitly demonstrated in the provided data points. Additionally, the lack of any detected nonce checks or capability checks across the plugin's entry points, while contributing to a zero attack surface, also means that no authorization or protection mechanisms are in place for any potential future extensions or code additions.
In conclusion, while "roots-hide-wp" v0.1 has demonstrated excellent security practices in its current form and has no known historical vulnerabilities, the use of `create_function` represents a potential, albeit currently unrealized, risk. The absence of any authorization checks (nonce or capability) should also be noted as a point of caution for future development, as it leaves any future additions to the plugin's functionality unprotected.
Key Concerns
- Use of dangerous function create_function
- Missing nonce checks
- Missing capability checks
Roots Hide WP Security Vulnerabilities
Roots Hide WP Code Analysis
Dangerous Functions Found
Output Escaping
Roots Hide WP Attack Surface
WordPress Hooks 32
Maintenance & Trust
Roots Hide WP Maintenance & Trust
Maintenance Signals
Community Trust
Roots Hide WP Alternatives
Nextend Social Login and Register
nextend-facebook-connect
One click registration & login plugin for Facebook, Google, X (formerly Twitter) and more. Quick setup and easy configuration.
Custom Twitter Feeds – A Tweets Widget or X Feed Widget
custom-twitter-feeds
Display X posts (Twitter tweets) from any public user account in a clean, attractive looking feed that updates weekly.
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic
shareaholic
Boost Audience Engagement with Award Winning Speed Optimized Social Tools: Share Buttons, Related Posts, Monetization & Google Analytics.
Roots Hide WP Developer Profile
4 plugins · 70 total installs
How We Detect Roots Hide WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/roots-hide-wp/roots-hide-wp.phpHTML / DOM Fingerprints
roots_nav_walker