Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Security & Risk Analysis

wordpress.org/plugins/webcraftic-updates-manager

Disable updates and automatic updates for WordPress core, plugins, and themes, with the option to disable plugin or theme updates individually.

9K active installs v1.3.0 PHP 7.4+ WP 5.6+ Updated Jan 12, 2026
disable-automatic-updatesdisable-core-updatesdisable-plugin-updatesdisable-updatesupdates-manager
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Safe to Use in 2026?

Generally Safe

Score 100/100

Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "webcraftic-updates-manager" plugin version 1.3.0 demonstrates a generally strong security posture, with no recorded vulnerabilities or critical taint flows. The presence of 16 nonce checks and 17 capability checks indicates a good effort to protect its entry points, and the absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. The plugin also has a very limited attack surface, with only one AJAX handler and no REST API routes or shortcodes.

However, a significant concern lies in the handling of SQL queries. All four SQL queries are executed without using prepared statements. This leaves the plugin vulnerable to SQL injection attacks, especially if any of the data used in these queries originates from user input. Additionally, while the majority of output escaping is properly handled (61%), there are still a notable number of outputs that are not escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped data is user-controlled.

Given the plugin's clean vulnerability history, it suggests that these potential issues have either not been exploited or have been mitigated by other factors. Despite these concerns, the plugin's robust use of nonces and capability checks, combined with a minimal attack surface, indicates a solid foundation for security. The primary focus for improvement should be on addressing the raw SQL queries and ensuring all outputs are properly escaped.

Key Concerns

  • Raw SQL queries without prepared statements
  • Unescaped output detected
Vulnerabilities
None known

Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
19
30 escaped
Nonce Checks
16
Capability Checks
17
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries

Output Escaping

61% escaped49 total outputs
Attack Surface

Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wbcr-upm-change-flagadmin\ajax\change-flag.php:55
WordPress Hooks 56
filterwbcr_factory_pages_483_imppage_rating_widget_urladmin\boot.php:30
filterwbcr/factory/pages/impressive/widgetsadmin\boot.php:39
filterwbcr_clearfy_group_optionsadmin\boot.php:107
filterwbcr_clearfy_allow_quick_modsadmin\boot.php:118
filterwbcr/factory/admin_noticesadmin\boot.php:169
actionadmin_noticesclearfy.php:47
actionnetwork_admin_noticesclearfy.php:48
actionplugins_loadedincludes\3rd-party\class-clearfy-plugin.php:43
actioninitincludes\3rd-party\class-clearfy-plugin.php:46
actionplugins_loadedincludes\class-plugin.php:48
actioninitincludes\class-plugin.php:51
filterthemeisle_sdk_productsincludes\class-plugin.php:57
filtersite_transient_update_pluginsincludes\classes\class-configurate-updates.php:28
actionadmin_initincludes\classes\class-configurate-updates.php:29
filterauto_update_pluginincludes\classes\class-configurate-updates.php:30
filterauto_update_pluginincludes\classes\class-configurate-updates.php:34
filtersite_transient_update_pluginsincludes\classes\class-configurate-updates.php:39
filterhttp_request_argsincludes\classes\class-configurate-updates.php:40
filtersite_transient_update_themesincludes\classes\class-configurate-updates.php:48
actionadmin_initincludes\classes\class-configurate-updates.php:49
filterauto_update_themeincludes\classes\class-configurate-updates.php:50
filterauto_update_themeincludes\classes\class-configurate-updates.php:53
filterauto_update_translationincludes\classes\class-configurate-updates.php:62
filterallow_major_auto_core_updatesincludes\classes\class-configurate-updates.php:74
filterallow_dev_auto_core_updatesincludes\classes\class-configurate-updates.php:75
filterallow_minor_auto_core_updatesincludes\classes\class-configurate-updates.php:76
filterallow_major_auto_core_updatesincludes\classes\class-configurate-updates.php:79
filterallow_dev_auto_core_updatesincludes\classes\class-configurate-updates.php:82
filterallow_minor_auto_core_updatesincludes\classes\class-configurate-updates.php:85
filterautomatic_updates_is_vcs_checkoutincludes\classes\class-configurate-updates.php:93
actionschedule_eventincludes\classes\class-configurate-updates.php:103
filtersite_transient_update_themesincludes\classes\class-configurate-updates.php:106
filterhttp_request_argsincludes\classes\class-configurate-updates.php:107
filtersite_transient_update_pluginsincludes\classes\class-configurate-updates.php:110
filtersite_transient_update_themesincludes\classes\class-configurate-updates.php:111
filterauto_core_update_send_emailincludes\classes\class-configurate-updates.php:118
filterauto_core_update_send_emailincludes\classes\class-configurate-updates.php:120
actionall_pluginsincludes\classes\class-configurate-updates.php:124
filterwp_get_update_dataincludes\classes\class-configurate-updates.php:125
actionwbcr_upmp_mail_updatesincludes\classes\class-configurate-updates.php:133
actionadmin_initincludes\classes\class-configurate-updates.php:270
actionadmin_initincludes\classes\class-configurate-updates.php:271
filterautomatic_updater_disabledincludes\classes\class-configurate-updates.php:279
filterallow_minor_auto_core_updatesincludes\classes\class-configurate-updates.php:280
filterallow_major_auto_core_updatesincludes\classes\class-configurate-updates.php:281
filterallow_dev_auto_core_updatesincludes\classes\class-configurate-updates.php:282
filterauto_update_coreincludes\classes\class-configurate-updates.php:283
filterwp_auto_update_coreincludes\classes\class-configurate-updates.php:284
filterauto_core_update_send_emailincludes\classes\class-configurate-updates.php:285
filtersend_core_update_notification_emailincludes\classes\class-configurate-updates.php:286
filterautomatic_updates_send_debug_emailincludes\classes\class-configurate-updates.php:287
filterautomatic_updates_is_vcs_checkoutincludes\classes\class-configurate-updates.php:288
filterwp_get_update_dataincludes\classes\class-configurate-updates.php:291
filtersite_transient_update_coreincludes\classes\class-configurate-updates.php:292
actionadmin_noticeswebcraftic-updates-manager.php:135
actionnetwork_admin_noticeswebcraftic-updates-manager.php:136

Scheduled Events 4

wp_update_plugins
wp_version_check
wp_update_themes
wp_maybe_auto_update
Maintenance & Trust

Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 12, 2026
PHP min version7.4
Downloads68K

Community Trust

Rating90/100
Number of ratings24
Active installs9K
Developer Profile

Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates Developer Profile

Themeisle

37 plugins · 2.2M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
420 days
View full developer profile
Detection Fingerprints

How We Detect Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/bootstrap-grid.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/bundle.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/dashboard.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/flatpickr.min.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/loaders.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/style.css/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/bundle.js/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/flatpickr.js+1 more
Script Paths
/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/bundle.js/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/flatpickr.js/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/scripts.js
Version Parameters
/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/bootstrap-grid.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/bundle.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/dashboard.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/flatpickr.min.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/loaders.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/css/style.css?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/bundle.js?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/flatpickr.js?ver=/wp-content/plugins/webcraftic-updates-manager/admin/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
wbcr-updates-managerwbcr-plugin-settings-pagewbcr-plugin-tabs-wrapwbcr-clearfy-settings-pagewbcr-factory-admin-page
HTML Comments
<!-- Developed by Alex Kovalev --><!-- Updates manager -->
Data Attributes
data-plugin-id="wbcr_updates_manager"
JS Globals
wbcr_upm_plugin_name
FAQ

Frequently Asked Questions about Disable Updates – Updates Manager, Disable Automatic Updates, Disable All Updates