Trash Fail Safe Security & Risk Analysis

wordpress.org/plugins/trash-fail-safe

Require confirmation before deleting items from the Trash, or emptying the whole Trash. Protects against accidental clicks.

40 active installs v1.2.2 PHP 5.3+ WP 4.7+ Updated Dec 4, 2025
adminconfirmationfailsafetrashtrashed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Trash Fail Safe Safe to Use in 2026?

Generally Safe

Score 100/100

Trash Fail Safe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the 'trash-fail-safe' v1.2.2 plugin exhibits a very strong security posture. The absence of any identified attack surface entry points, such as AJAX handlers, REST API routes, or shortcodes, significantly limits the potential for external attackers to interact with the plugin. Furthermore, the code analysis shows a complete lack of dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. There are no file operations or external HTTP requests, and crucially, there are no nonce or capability checks reported, which *could* be a concern in plugins with active entry points, but is irrelevant here due to the lack of such points.

The vulnerability history is also entirely clear, with zero known CVEs recorded for this plugin. This suggests a history of secure development and maintenance. The lack of any common vulnerability types further reinforces this positive assessment.

In conclusion, the 'trash-fail-safe' v1.2.2 plugin appears to be exceptionally secure. The lack of any identified entry points and the clean code analysis results, combined with a spotless vulnerability history, present a minimal security risk. While the absence of nonce and capability checks on entry points is typically a concern, it is not a weakness in this specific case because there are no entry points to protect. The plugin's design inherently limits its attack surface to practically zero.

Vulnerabilities
None known

Trash Fail Safe Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Trash Fail Safe Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Trash Fail Safe Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_enqueue_scriptstrash-fail-safe.php:25
Maintenance & Trust

Trash Fail Safe Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version5.3
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

Trash Fail Safe Developer Profile

mikehealy

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Trash Fail Safe

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/trash-fail-safe/failsafe.js
Script Paths
/wp-content/plugins/trash-fail-safe/failsafe.js
Version Parameters
trash-fail-safe/failsafe.js?ver=1.2.1

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Trash Fail Safe