Tidy Archives Security & Risk Analysis

wordpress.org/plugins/tidy-archives

Tidy Archives displays your archives in a more practical way.

10 active installs v1.0 PHP + WP 2.9+ Updated Unknown
archivestidy
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Tidy Archives Safe to Use in 2026?

Generally Safe

Score 100/100

Tidy Archives has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "tidy-archives" v1.0 plugin exhibits a generally good security posture with a zero attack surface, meaning it does not expose any direct entry points through AJAX, REST API, shortcodes, or cron events without proper authentication or permission checks. Furthermore, the absence of critical or high-severity taint flows and known CVEs suggests a level of code maturity and a lack of historically exploited vulnerabilities. The plugin also avoids dangerous functions and external HTTP requests, further contributing to its secure design.

Key Concerns

  • Output escaping not implemented
  • SQL queries not consistently prepared
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Tidy Archives Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Tidy Archives Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

0% escaped5 total outputs
Attack Surface

Tidy Archives Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Tidy Archives Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Tidy Archives Developer Profile

Jean

6 plugins · 340 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tidy Archives

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<ul><li><a href=""></a></li>
FAQ

Frequently Asked Questions about Tidy Archives