
Tailored Easy Exclude Security & Risk Analysis
wordpress.org/plugins/tailored-easy-excludeSmall plugin that allows you to exclude pages or posts from WordPress administration post/page listing, and post/page can be excluded per user role.
Is Tailored Easy Exclude Safe to Use in 2026?
Generally Safe
Score 85/100Tailored Easy Exclude has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tailored-easy-exclude v1.1 plugin exhibits a generally good security posture with no known historical vulnerabilities or critical code signals. The absence of known CVEs and common vulnerability types is a strong positive indicator. Furthermore, the plugin demonstrates sound practices by exclusively using prepared statements for its single SQL query and avoiding file operations and external HTTP requests, minimizing common attack vectors.
However, there are notable concerns stemming from the static analysis. The primary weakness lies in the output escaping, with only 17% of outputs being properly escaped, leaving a significant portion vulnerable to cross-site scripting (XSS) attacks. Additionally, the taint analysis revealed a flow with an unsanitized path, which, while not flagged as critical or high severity in this analysis, represents a potential entry point for malicious input that could be exploited if combined with other weaknesses or specific usage patterns. The lack of nonce and capability checks across all entry points also leaves the plugin susceptible to CSRF attacks and unauthorized access if any entry points were to be discovered or added in the future.
In conclusion, while the plugin avoids many common pitfalls and has a clean vulnerability history, the poor output escaping and the identified unsanitized taint flow are significant weaknesses that require attention. The absence of protective measures like nonce and capability checks on its entry points, though currently zero, indicates a lack of defensive programming that could become a problem. Addressing the output escaping and investigating the unsanitized taint flow are the most immediate priorities for improving the plugin's security.
Key Concerns
- Low percentage of properly escaped output
- Unsanitized path in taint flow
- Missing nonce checks on entry points
- Missing capability checks on entry points
Tailored Easy Exclude Security Vulnerabilities
Tailored Easy Exclude Release Timeline
Tailored Easy Exclude Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Tailored Easy Exclude Attack Surface
WordPress Hooks 11
Maintenance & Trust
Tailored Easy Exclude Maintenance & Trust
Maintenance Signals
Community Trust
Tailored Easy Exclude Alternatives
Search Exclude
search-exclude
Hide any post or page from the search results.
Exclude Pages
exclude-pages
This plugin adds a checkbox, “include this page in menus”, uncheck this to exclude pages from the page navigation that users see on your site.
Exclude Pages From Menu
exclude-pages-from-menu
The plugin provides option in the page edit screen to remove page from navigation menu in the front end of site.
Exclude Search
exclude-search
Exclude posts, pages, products or custom posts from WordPress search results.
CleanCodeNZ Exclude Pages Plugin
cleancode-exclude-pages
This is a plugin to hide pages from navigation and/or search results using custom fields, parent and child pages are supported too
Tailored Easy Exclude Developer Profile
1 plugin · 30 total installs
How We Detect Tailored Easy Exclude
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tailored-easy-exclude/assets/css/chosen.css/wp-content/plugins/tailored-easy-exclude/assets/js/chosen.jquery.min.js/wp-content/plugins/tailored-easy-exclude/assets/js/admin.js/wp-content/plugins/tailored-easy-exclude/assets/js/chosen.jquery.min.js/wp-content/plugins/tailored-easy-exclude/assets/js/admin.jstailored-easy-exclude/assets/css/chosen.css?ver=tailored-easy-exclude/assets/js/chosen.jquery.min.js?ver=tailored-easy-exclude/assets/js/admin.js?ver=HTML / DOM Fingerprints
data-placeholder