
Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Security & Risk Analysis
wordpress.org/plugins/webcraftic-updates-managerDisable updates and automatic updates for WordPress core, plugins, and themes, with the option to disable plugin or theme updates individually.
Is Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Safe to Use in 2026?
Generally Safe
Score 100/100Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "webcraftic-updates-manager" plugin version 1.3.0 demonstrates a generally strong security posture, with no recorded vulnerabilities or critical taint flows. The presence of 16 nonce checks and 17 capability checks indicates a good effort to protect its entry points, and the absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. The plugin also has a very limited attack surface, with only one AJAX handler and no REST API routes or shortcodes.
However, a significant concern lies in the handling of SQL queries. All four SQL queries are executed without using prepared statements. This leaves the plugin vulnerable to SQL injection attacks, especially if any of the data used in these queries originates from user input. Additionally, while the majority of output escaping is properly handled (61%), there are still a notable number of outputs that are not escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controlled.
Given the plugin's clean vulnerability history, it suggests that these potential issues have either not been exploited or have been mitigated by other factors. Despite these concerns, the plugin's robust use of nonces and capability checks, combined with a minimal attack surface, indicates a solid foundation for security. The primary focus for improvement should be on addressing the raw SQL queries and ensuring all outputs are properly escaped.
Key Concerns
- Raw SQL queries without prepared statements
- Unescaped output detected
Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Security Vulnerabilities
Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Code Analysis
SQL Query Safety
Output Escaping
Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Attack Surface
AJAX Handlers 1
WordPress Hooks 56
Scheduled Events 4
Maintenance & Trust
Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Maintenance & Trust
Maintenance Signals
Community Trust
Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Alternatives
WP Disable Automatic Updates
wp-disable-automatic-updates
This plugin allows you to disable all types of automatic Wordpress Updates very simply with some special features.
Easy Updates Manager
stops-core-theme-and-plugin-updates
Manage all your WordPress updates, including individual updates, automatic updates, logs, and loads more. This also works very well with WordPress Mul …
Ignore Or Disable Plugin Update
ignore-single-update
Allows to ignore a single plugin update for a certain number of days, or until its next version.
Disable All WordPress Updates
disable-wordpress-updates
Disables the theme, plugin and core update checking, the related cronjobs, plugin/theme update health checks and notification system.
Disable Updates for WordPress Core, Plugins and Themes
disable-updates
Disables the WordPress update checking and notification system for all core, plugin and theme updates.
Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Developer Profile
37 plugins · 2.2M total installs
How We Detect Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/bootstrap-grid.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/bundle.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/dashboard.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/flatpickr.min.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/loaders.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/style.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/bundle.js/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/flatpickr.js+1 more/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/bundle.js/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/flatpickr.js/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/scripts.js/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/bootstrap-grid.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/bundle.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/dashboard.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/flatpickr.min.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/loaders.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/style.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/bundle.js?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/flatpickr.js?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/scripts.js?ver=HTML / DOM Fingerprints
wbcr-updates-managerwbcr-plugin-settings-pagewbcr-plugin-tabs-wrapwbcr-clearfy-settings-pagewbcr-factory-admin-page<!-- Developed by Alex Kovalev --><!-- Updates manager -->data-plugin-id="wbcr_updates_manager"wbcr_upm_plugin_name