Version Pilot – Plugin Update Manager Security & Risk Analysis

wordpress.org/plugins/version-pilot

Provides an efficient, secure, and user-friendly version update mechanism for non-official WordPress plugins.

0 active installs v2.1.0 PHP 7.0+ WP 5.6+ Updated Sep 5, 2025
auto-updatecustom-updaterplugin-updaterself-hostedversion-control
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Version Pilot – Plugin Update Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Version Pilot – Plugin Update Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

Version-Pilot v2.1.0 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The plugin adheres to good security practices by using prepared statements for all SQL queries and properly escaping nearly all output. It also implements nonce and capability checks on its entry points, significantly reducing the risk of common WordPress vulnerabilities. The absence of dangerous functions, file operations, external HTTP requests, and shortcodes further contributes to a limited attack surface. The vulnerability history is clean, with no recorded CVEs, indicating a potentially well-maintained and secure codebase.

However, one area of concern is the presence of a single taint flow with an unsanitized path. While classified as low severity in this analysis, such flows can still be exploited under specific circumstances to potentially lead to unexpected behavior or information disclosure. The static analysis identifies one AJAX handler, but it appears to be protected by authentication checks, which is a positive sign. The plugin's minimal attack surface is a significant strength, but the single unsanitized path warrants attention and review to ensure no potential exploits exist.

In conclusion, Version-Pilot v2.1.0 is a relatively secure plugin with a commendable focus on secure coding practices. The lack of historical vulnerabilities is a positive indicator. The primary weakness identified is the single unsanitized path, which, while not flagged as critical or high severity, should be investigated to confirm its benign nature. Overall, the plugin appears to be a low-risk option, but vigilance regarding the identified taint flow is advised.

Key Concerns

  • Flows with unsanitized paths found
Vulnerabilities
None known

Version Pilot – Plugin Update Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Version Pilot – Plugin Update Manager Release Timeline

v2.1.0Current
v2.0.0
Code Analysis
Analyzed Mar 17, 2026

Version Pilot – Plugin Update Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
97 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped98 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

4 flows1 with unsanitized paths
prefill_new_version_data (admin\class-version-pilot-admin.php:450)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Version Pilot – Plugin Update Manager Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_version_pilot_toggle_version_statusadmin\class-version-pilot-admin.php:69
WordPress Hooks 24
actionadd_meta_boxesadmin\class-version-pilot-admin.php:50
actionsave_postadmin\class-version-pilot-admin.php:51
actionadmin_enqueue_scriptsadmin\class-version-pilot-admin.php:52
filtermanage_version_pilot_plugin_posts_columnsadmin\class-version-pilot-admin.php:55
actionmanage_version_pilot_plugin_posts_custom_columnadmin\class-version-pilot-admin.php:56
filterpost_row_actionsadmin\class-version-pilot-admin.php:57
filterenter_title_hereadmin\class-version-pilot-admin.php:58
filtermanage_wvp_plugin_version_posts_columnsadmin\class-version-pilot-admin.php:61
actionmanage_wvp_plugin_version_posts_custom_columnadmin\class-version-pilot-admin.php:62
filterthe_titleadmin\class-version-pilot-admin.php:63
actionrestrict_manage_postsadmin\class-version-pilot-admin.php:64
filterparse_queryadmin\class-version-pilot-admin.php:65
actionadmin_head-post-new.phpadmin\class-version-pilot-admin.php:66
actionsave_postadmin\class-version-pilot-admin.php:187
actionadmin_noticesadmin\class-version-pilot-admin.php:465
actioninitincludes\class-version-pilot-post-type.php:27
actionrest_api_initincludes\class-version-pilot-rest-api.php:35
filterversion_pilot_menu_namepro\admin\class-version-pilot-pro-admin.php:32
actionversion_pilot_after_version_number_metabox_fieldpro\admin\class-version-pilot-pro-admin.php:33
filterversion_pilot_version_savable_fieldspro\admin\class-version-pilot-pro-admin.php:34
actionversion_pilot_admin_enqueue_scriptspro\admin\class-version-pilot-pro-admin.php:35
filterversion_pilot_version_columnspro\admin\class-version-pilot-pro-admin.php:36
actionmanage_wvp_plugin_version_posts_custom_columnpro\admin\class-version-pilot-pro-admin.php:37
filterversion_pilot_get_plugin_datapro\publics\class-version-pilot-pro-publics.php:54
Maintenance & Trust

Version Pilot – Plugin Update Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 5, 2025
PHP min version7.0
Downloads322

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Version Pilot – Plugin Update Manager Developer Profile

wowown

4 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Version Pilot – Plugin Update Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/version-pilot/admin/css/version-pilot-admin.css/wp-content/plugins/version-pilot/admin/js/version-pilot-admin.js/wp-content/plugins/version-pilot/admin/js/version-pilot-admin-vendors.js
Script Paths
/wp-content/plugins/version-pilot/admin/js/version-pilot-admin.js/wp-content/plugins/version-pilot/admin/js/version-pilot-admin-vendors.js
Version Parameters
version-pilot/admin/css/version-pilot-admin.css?ver=version-pilot/admin/js/version-pilot-admin.js?ver=version-pilot/admin/js/version-pilot-admin-vendors.js?ver=

HTML / DOM Fingerprints

CSS Classes
version_pilot_plugin_slugversion_pilot_plugin_homepage_urlversion_pilot_plugin_requires_wpversion_pilot_plugin_requires_phpversion_pilot_plugin_banner_lowversion_pilot_plugin_banner_highversion_pilot_version_numberversion_pilot_package_url+2 more
Data Attributes
data-plugin-slugdata-plugin-iddata-version-id
JS Globals
version_pilot_ajax_object
REST Endpoints
/wp-json/version-pilot/v1/toggle-version-status
FAQ

Frequently Asked Questions about Version Pilot – Plugin Update Manager