Unplug Jetpack Security & Risk Analysis

wordpress.org/plugins/unplug-jetpack

Use Jetpack without needing to connect to WordPress.com

2K active installs v0.1.1 PHP + WP 3.5.1+ Updated Feb 7, 2015
jetpack
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Unplug Jetpack Safe to Use in 2026?

Generally Safe

Score 85/100

Unplug Jetpack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "unplug-jetpack" v0.1.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points (AJAX handlers, REST API routes, shortcodes, cron events) significantly reduces the potential for external exploitation. Furthermore, the code signals indicate good development practices, with no dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. The plugin also avoids file operations, external HTTP requests, and relies on robust security checks like nonce and capability checks where appropriate (though the lack of these checks is noted due to the zero attack surface).

The vulnerability history for this plugin is clean, with no known CVEs recorded. This suggests a history of secure development and maintenance, or a lack of past scrutiny. While the zero attack surface and clean vulnerability history are positive indicators, the complete absence of any identified flows in the taint analysis, alongside the lack of nonce and capability checks, could be a consequence of the plugin's simplicity or a lack of complex interactions that would typically reveal such flows. However, given the current data, the plugin appears to be secure and well-developed.

Vulnerabilities
None known

Unplug Jetpack Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Unplug Jetpack Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Unplug Jetpack Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Unplug Jetpack Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterjetpack_development_modeunplug-jetpack.php:31
actionplugins_loadedunplug-jetpack.php:33
Maintenance & Trust

Unplug Jetpack Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.0
Last updatedFeb 7, 2015
PHP min version
Downloads36K

Community Trust

Rating100/100
Number of ratings5
Active installs2K
Developer Profile

Unplug Jetpack Developer Profile

Tanner Moushey

3 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Unplug Jetpack

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Unplug Jetpack