
Unplug Security & Risk Analysis
wordpress.org/plugins/unplugCut the plugin bloat. See which plugins are actually being used on your sites and which ones are just plugin bloat.
Is Unplug Safe to Use in 2026?
Generally Safe
Score 100/100Unplug has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "unplug" v1.3.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices, with a very high percentage of SQL queries using prepared statements and output being properly escaped. The absence of dangerous functions and critical or high severity taint analysis flows further contributes to a generally robust codebase. Furthermore, the plugin has a clean vulnerability history, with no recorded CVEs, suggesting a commitment to security or simply a lack of prior discovery of vulnerabilities.
However, a significant concern arises from the substantial attack surface exposed through AJAX handlers, with 27 out of 31 handlers lacking authentication checks. This presents a considerable risk, as unauthorized users could potentially interact with these endpoints and trigger unintended actions. While the plugin has a low number of file operations and external HTTP requests, and uses nonces and capability checks reasonably well for its available code signals, the sheer volume of unprotected AJAX entry points is a major vulnerability in its current state. The plugin's strengths in secure coding practices are unfortunately undermined by this exposure.
In conclusion, while "unplug" v1.3.0 demonstrates excellent internal coding hygiene concerning SQL and output handling, its security is severely compromised by a large, unprotected AJAX attack surface. The lack of past vulnerabilities is a positive indicator but does not negate the immediate and substantial risk posed by the unprotected AJAX endpoints. Addressing these unprotected handlers should be the highest priority to improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
Unplug Security Vulnerabilities
Unplug Code Analysis
SQL Query Safety
Output Escaping
Unplug Attack Surface
AJAX Handlers 31
REST API Routes 1
WordPress Hooks 43
Scheduled Events 4
Maintenance & Trust
Unplug Maintenance & Trust
Maintenance Signals
Community Trust
Unplug Alternatives
Freesoul Deactivate Plugins – Disable plugins on individual WordPress pages
freesoul-deactivate-plugins
Load plugins only where you need them. No bloat, no conflicts, more speed. Deactivate plugins where they don't add anything useful.
Lazy Load Control For Elementor – Remove the Lazy Load attribute from specific images in Elementor
lazy-load-control-for-elementor
Remove the Lazy Load attribute from specific images in Elementor.
WP Performance
wp-performance
WP Performance is a cache & performance plugin which makes optimizing your site really easy.
Asset Preloader: preload the assets only on the pages where you need it
asset-preloader
Decide which assets you want to preload depending on the page.
Preload Everything
preload-everything
Fasten Your Website Loading Speed By Preloading Internal Pages Ahead Of The Time For Your Visitors.
Unplug Developer Profile
1 plugin · 0 total installs
How We Detect Unplug
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unplug/admin/css/unplug-admin-main.css/wp-content/plugins/unplug/admin/js/unplug-admin-main.js/wp-content/plugins/unplug/public/css/unplug-public-main.css/wp-content/plugins/unplug/public/js/unplug-public-main.js/wp-content/plugins/unplug/admin/js/unplug-admin-main.js/wp-content/plugins/unplug/public/js/unplug-public-main.jsunplug/admin/css/unplug-admin-main.css?ver=unplug/admin/js/unplug-admin-main.js?ver=unplug/public/css/unplug-public-main.css?ver=unplug/public/js/unplug-public-main.js?ver=HTML / DOM Fingerprints
unplug-admin-sectionunplug-spinnerunplug-progress-barunplug-log-outputunplug-modalunplug-scan-results<!-- Unplug Admin notices --><!-- Unplug Scan Results --><!-- Unplug Plugin List --><!-- Unplug Queue -->+1 moredata-unplug-task-iddata-unplug-noncedata-unplug-actionunplug_ajax_object/wp-json/unplug/v1/scan/wp-json/unplug/v1/settings