Stop Auto Updating Dangit Security & Risk Analysis

wordpress.org/plugins/stop-auto-update

This plugin simply stop WordPress from automatically updating for you.

40 active installs v0.14.14 PHP + WP 3.0+ Updated Apr 20, 2014
automaticautomaticallydisableupdatedupdater
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Stop Auto Updating Dangit Safe to Use in 2026?

Generally Safe

Score 85/100

Stop Auto Updating Dangit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'stop-auto-update' plugin version 0.14.14 demonstrates a generally positive security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are all prepared, no file operations or external HTTP requests are made, and no critical or high-severity taint flows were detected. The plugin also has no recorded vulnerabilities, suggesting a history of stable and secure operation.

However, a significant concern arises from the complete lack of output escaping. This means that any dynamic content displayed by the plugin is not being properly sanitized, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks and capability checks on the zero identified AJAX handlers, while the attack surface is currently zero, indicates a potential for future security weaknesses if functionality is added without proper security controls. The lack of any detected taint flows might be due to the limited scope of the analysis or the plugin's current minimal functionality.

In conclusion, while the plugin benefits from a clean vulnerability history and the absence of common risky code patterns, the unescaped output is a critical flaw that significantly elevates its risk profile. The lack of authorization checks on even the minimal attack surface also represents a latent risk. Addressing the output escaping issue should be the immediate priority for improving the plugin's security.

Key Concerns

  • Output escaping is missing
  • No capability checks on AJAX
  • No nonce checks on AJAX
Vulnerabilities
None known

Stop Auto Updating Dangit Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Stop Auto Updating Dangit Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Stop Auto Updating Dangit Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_initindex.php:28
filterautomatic_updater_disabledindex.php:29
Maintenance & Trust

Stop Auto Updating Dangit Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedApr 20, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Stop Auto Updating Dangit Developer Profile

Eli

9 plugins · 101K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
782 days
View full developer profile
Detection Fingerprints

How We Detect Stop Auto Updating Dangit

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
stop-auto-update-dangit

HTML / DOM Fingerprints

Data Attributes
name="aud_stop_updating"value="1"
FAQ

Frequently Asked Questions about Stop Auto Updating Dangit