
Roots Plug Security & Risk Analysis
wordpress.org/plugins/roots-plugCatch-all awesomeness for a leaner, meaner WordPress site.
Is Roots Plug Safe to Use in 2026?
Generally Safe
Score 85/100Roots Plug has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "roots-plug" v1.2.4 exhibits a generally strong security posture based on the static analysis and vulnerability history provided. The absence of any known CVEs, unpatched vulnerabilities, or recorded common vulnerability types suggests a well-maintained and secure plugin over time. The static analysis further reinforces this impression with a clean bill of health regarding SQL queries (all prepared), output escaping, file operations, and external HTTP requests. Crucially, there are no identified critical or high-severity taint flows, indicating that user-supplied data is likely being handled safely.
However, the presence of two instances of the `create_function()` usage is a significant concern. While the static analysis did not identify any exploitable flows directly stemming from this, `create_function()` is deprecated and can be a vector for code injection if its usage isn't meticulously controlled and sanitized. The absence of any nonce checks, combined with a lack of specific capability checks on the identified entry points (though the attack surface is zero), also leaves room for potential issues if the plugin were to be extended or modified in the future.
Overall, "roots-plug" v1.2.4 appears robust in its current state, particularly due to its clean vulnerability history and adherence to secure coding practices for most aspects. The primary weakness lies in the use of a deprecated and potentially risky function. Further investigation into the specific implementation of `create_function()` would be recommended to confirm its safe usage.
Key Concerns
- Use of deprecated and potentially risky function
- Lack of nonce checks
Roots Plug Security Vulnerabilities
Roots Plug Code Analysis
Dangerous Functions Found
Output Escaping
Roots Plug Attack Surface
WordPress Hooks 27
Maintenance & Trust
Roots Plug Maintenance & Trust
Maintenance Signals
Community Trust
Roots Plug Alternatives
Redirection
redirection
Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.
WP-Sweep
wp-sweep
WP-Sweep allows you to clean up unused, orphaned and duplicated data in your WordPress. It also optimizes your database tables.
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
Htaccess File Editor – Safely Edit Htaccess File
wp-htaccess-editor
A safe & simple htaccess file editor with automatic htaccess backups & htaccess file syntax testing.
Delete Duplicate Posts
delete-duplicate-posts
Get rid of duplicate posts and pages (any post type) on your blog with manual or automatic modes.
Roots Plug Developer Profile
3 plugins · 1K total installs
How We Detect Roots Plug
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/roots-plug/RootsPlug/rootsplug.css/wp-content/plugins/roots-plug/RootsPlug/rootsplug.js/wp-content/plugins/roots-plug/RootsPlug/rootsplug.jsroots-plug/rootsplug.css?ver=roots-plug/rootsplug.js?ver=HTML / DOM Fingerprints
rootsplug-embed-wrap<!-- Roots Plug: Cleanup --><!-- Roots Plug: Addons --><!-- Roots Plug: Htaccess -->data-rootsplug-original-srcRootsPlug