Website Open/Closed Toggle Security & Risk Analysis

wordpress.org/plugins/website-openclosed-toggle

This plugin allows you to easily open and close your website and display a custom message or HTML page when closed.

500 active installs v0.3.9.1 PHP + WP 4.3+ Updated Dec 14, 2023
closeclosedopenopenedwebsite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Website Open/Closed Toggle Safe to Use in 2026?

Generally Safe

Score 85/100

Website Open/Closed Toggle has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The website-openclosed-toggle plugin v0.3.9.1 demonstrates a generally good security posture based on the provided static analysis. The absence of any known CVEs and the plugin's vulnerability history indicate a mature and well-maintained codebase, or at least one that hasn't attracted significant security scrutiny. The code analysis reveals no dangerous functions, no raw SQL queries, and no file operations, all positive signs. Taint analysis also shows no identified vulnerabilities.

However, there are areas for improvement. The plugin makes an external HTTP request, which could be a vector for various attacks if not handled securely, though the analysis doesn't detail how this request is made or if it's properly sanitized. A more significant concern is the output escaping. With 56% of outputs properly escaped, a substantial portion (44%) remains unescaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. While the attack surface is reported as zero, this might be an artifact of the analysis tool's limitations or the plugin's specific functionality. The single nonce check and zero capability checks suggest potential weaknesses in securing its functionalities, although the lack of an attack surface limits the immediate impact.

Key Concerns

  • Output escaping is only 56% proper
  • External HTTP request made
  • Only one nonce check
  • Zero capability checks
Vulnerabilities
None known

Website Open/Closed Toggle Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Website Open/Closed Toggle Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
10 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

56% escaped18 total outputs
Attack Surface

Website Open/Closed Toggle Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptswebsite-openclosed-toggle.php:49
actionadmin_menuwebsite-openclosed-toggle.php:50
actiontemplate_redirectwebsite-openclosed-toggle.php:51
actiontemplate_redirectwebsite-openclosed-toggle.php:52
filterplugin_action_linkswebsite-openclosed-toggle.php:54
Maintenance & Trust

Website Open/Closed Toggle Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 14, 2023
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings1
Active installs500
Developer Profile

Website Open/Closed Toggle Developer Profile

RSimpson

2 plugins · 700 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Website Open/Closed Toggle

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/website-openclosed-toggle/woct/css/style.css
Version Parameters
website-openclosed-toggle/woct/css/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Website Open/Closed Toggle