Show/Hide Updates Exclusive Security & Risk Analysis

wordpress.org/plugins/showhide-updates-exclusive

This plugin hides all update notifications for Wordpress core, plugin and theme updates in Wordpress admin for all users except users whom administrat …

0 active installs v1.0.0 PHP 7.0.0+ WP 4.9.8+ Updated Dec 27, 2018
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Show/Hide Updates Exclusive Safe to Use in 2026?

Generally Safe

Score 85/100

Show/Hide Updates Exclusive has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

Based on the provided static analysis, the "showhide-updates-exclusive" v1.0.0 plugin exhibits a strong security posture. The absence of any identified entry points, including AJAX handlers, REST API routes, shortcodes, and cron events, significantly minimizes its attack surface. Furthermore, the code analysis indicates a lack of dangerous functions, no file operations, and no external HTTP requests, all of which are positive indicators. The fact that 100% of SQL queries use prepared statements and all output is properly escaped demonstrates good development practices in preventing common web vulnerabilities.

While the code analysis reveals no critical or high-severity issues in taint analysis and the plugin has no recorded vulnerability history, it's important to note the absence of nonce checks and the presence of only two capability checks. In scenarios where functionality might evolve or be extended in future versions, these could become points of concern if not carefully managed. However, with the current version and the disclosed analysis, the plugin appears to be very secure due to its minimal attack surface and adherence to secure coding principles.

In conclusion, "showhide-updates-exclusive" v1.0.0 presents a very low security risk. Its strengths lie in its extremely limited attack surface and the developer's apparent commitment to secure coding practices like prepared statements and output escaping. The main areas for potential future monitoring, although not current critical flaws, would be related to the limited number of capability checks and the complete absence of nonce checks, which could be important for future extensibility.

Vulnerabilities
None known

Show/Hide Updates Exclusive Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Show/Hide Updates Exclusive Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Show/Hide Updates Exclusive Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 25
filterinitshow-hide-updates-exclusive.php:46
actionshow_user_profileshow-hide-updates-exclusive.php:47
actionedit_user_profileshow-hide-updates-exclusive.php:48
actionpersonal_options_updateshow-hide-updates-exclusive.php:49
actionedit_user_profile_updateshow-hide-updates-exclusive.php:50
actionadmin_initshow-hide-updates-exclusive.php:68
filterpre_site_transient_update_themesshow-hide-updates-exclusive.php:73
filterpre_site_transient_update_pluginsshow-hide-updates-exclusive.php:78
filterpre_site_transient_update_coreshow-hide-updates-exclusive.php:83
actionschedule_eventshow-hide-updates-exclusive.php:88
filterauto_update_translationshow-hide-updates-exclusive.php:93
filterautomatic_updater_disabledshow-hide-updates-exclusive.php:94
filterallow_minor_auto_core_updatesshow-hide-updates-exclusive.php:95
filterallow_major_auto_core_updatesshow-hide-updates-exclusive.php:96
filterallow_dev_auto_core_updatesshow-hide-updates-exclusive.php:97
filterauto_update_coreshow-hide-updates-exclusive.php:98
filterwp_auto_update_coreshow-hide-updates-exclusive.php:99
filterauto_core_update_send_emailshow-hide-updates-exclusive.php:100
filtersend_core_update_notification_emailshow-hide-updates-exclusive.php:101
filterauto_update_pluginshow-hide-updates-exclusive.php:102
filterauto_update_themeshow-hide-updates-exclusive.php:103
filterautomatic_updates_send_debug_emailshow-hide-updates-exclusive.php:104
filterautomatic_updates_is_vcs_checkoutshow-hide-updates-exclusive.php:105
filterautomatic_updates_send_debug_email show-hide-updates-exclusive.php:107
filterpre_http_requestshow-hide-updates-exclusive.php:114
Maintenance & Trust

Show/Hide Updates Exclusive Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedDec 27, 2018
PHP min version7.0.0
Downloads919

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Show/Hide Updates Exclusive Alternatives

No alternatives data available yet.

Developer Profile

Show/Hide Updates Exclusive Developer Profile

PRESSMAN

20 plugins · 100 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Show/Hide Updates Exclusive

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- Show Update --><!-- Show -->
Data Attributes
data-updater
FAQ

Frequently Asked Questions about Show/Hide Updates Exclusive