
Simple Revisions Delete Security & Risk Analysis
wordpress.org/plugins/simple-revisions-deleteSimple Revisions Delete adds a discreet link within a post submit box to let you purge (delete) its revisions via AJAX. Bulk actions also available.
Is Simple Revisions Delete Safe to Use in 2026?
Generally Safe
Score 100/100Simple Revisions Delete has a strong security track record. Known vulnerabilities have been patched promptly.
The 'simple-revisions-delete' plugin version 1.5.5 presents a mixed security posture. On the positive side, it demonstrates good practices by implementing nonce checks and capability checks for its entry points, and it has a very limited attack surface with no shortcodes, cron events, or REST API routes. Furthermore, all SQL queries utilize prepared statements, and there are no identified dangerous functions, file operations, or external HTTP requests, which significantly reduces common attack vectors. The taint analysis also shows no identified security issues.
However, a significant concern arises from the static analysis indicating that 0% of output escaping is properly handled. This means that any data outputted by the plugin, even if indirectly influenced by user input, could be vulnerable to Cross-Site Scripting (XSS) attacks if not properly sanitized before display. While the vulnerability history shows no currently unpatched CVEs, the presence of one past CVE, specifically identified as Cross-Site Request Forgery (CSRF), and the date of the last vulnerability (March 2024) suggest that the plugin has had security issues in the past and might require vigilant monitoring for future patches. The lack of unpatched vulnerabilities is a positive sign, but the past history and the output escaping issue warrant attention.
In conclusion, while the plugin benefits from a small attack surface and secure database practices, the complete lack of output escaping is a critical weakness that exposes users to potential XSS vulnerabilities. The historical presence of a CSRF vulnerability, though now patched, also suggests a need for continued vigilance. Developers should prioritize addressing the output escaping issue to improve the plugin's overall security.
Key Concerns
- 0% output escaping detected
- 1 historical CVE (CSRF)
Simple Revisions Delete Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Revisions Delete <= 1.5.3 - Cross-Site Request Forgery
Simple Revisions Delete Code Analysis
Output Escaping
Simple Revisions Delete Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Simple Revisions Delete Maintenance & Trust
Maintenance Signals
Community Trust
Simple Revisions Delete Alternatives
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
Delete Duplicate Posts
delete-duplicate-posts
Get rid of duplicate posts and pages (any post type) on your blog with manual or automatic modes.
Delete Posts automatically
delete-old-posts-programmatically
The Delete Posts Automatically plugin keeps your website clean by programmatically deleting posts using a wide range of powerful filters.
Delete Post with Attachments
delete-post-with-attachments
A simple plugin to delete attached media files e.g. images/videos/documents, when the post is deleted. Supports Elementor, Divi Builder, Thrive Archit …
Delete Duplicate Products for WooCommerce
delete-duplicate-products-for-woocommerce
Quickly find and manage duplicate WooCommerce products. Bulk delete, image control, action logging, 301 redirects, and CSV export.
Simple Revisions Delete Developer Profile
3 plugins · 61K total installs
How We Detect Simple Revisions Delete
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-revisions-delete/js/wpsrd-admin-script.js/wp-content/plugins/simple-revisions-delete/js/wpsrd-gutenberg-script.js/wp-content/plugins/simple-revisions-delete/js/wpsrd-admin-script.js/wp-content/plugins/simple-revisions-delete/js/wpsrd-gutenberg-script.jssimple-revisions-delete/js/wpsrd-admin-script.js?ver=1.5simple-revisions-delete/js/wpsrd-gutenberg-script.js?ver=1.5HTML / DOM Fingerprints
wpsrd-clear-revisionswpsrd-no-jswpsrd-loadingwpsrd-linkwpsrd-dismisswpsrd-btnSECURITY : Exit if accessed directlyCopyright 2015 Brice CAPOBIANCO (contact : http://b-website.com/contact)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, as+22 moredata-wpsrd-clear-revisions-noncewpsrd_clear_revisions_nonce