
WH Tweaks Security & Risk Analysis
wordpress.org/plugins/wh-tweaksCommon functionality WordPress core should have but maybe shouldn't.
Is WH Tweaks Safe to Use in 2026?
Generally Safe
Score 99/100WH Tweaks has a strong security track record. Known vulnerabilities have been patched promptly.
The "wh-tweaks" v1.0.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and maintaining a high percentage of properly escaped output. The absence of dangerous functions, file operations, and external HTTP requests is also a good sign. However, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks, creating potential entry points for unauthorized actions. Furthermore, the complete absence of nonce checks on these AJAX endpoints exacerbates the risk, as it leaves them vulnerable to Cross-Site Request Forgery (CSRF) attacks. While the plugin has no currently unpatched vulnerabilities, its history includes one medium-severity Cross-site Scripting (XSS) vulnerability, which, despite being patched in past versions, highlights a past weakness in input sanitization or output escaping that needs continued vigilance. The lack of taint analysis data also makes it difficult to fully assess the impact of any potential unvalidated data flows.
Key Concerns
- AJAX handlers without auth checks
- Missing nonce checks on AJAX
- Medium severity vulnerability history
WH Tweaks Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WH Tweaks <= 1.0.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
WH Tweaks Code Analysis
Output Escaping
WH Tweaks Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 43
Maintenance & Trust
WH Tweaks Maintenance & Trust
Maintenance Signals
Community Trust
WH Tweaks Alternatives
Hotfix
hotfix
Provides unofficial fixes for selected WordPress bugs, so you don't have to wait for the next WordPress core release.
WP_PingPreserver
wp-pingpreserver
Prevents WordPress from eating pings that come too quickly in succession (i.e. a single post linking to more than one of your pages).
GA Google Analytics – Connect Google Analytics to WordPress
ga-google-analytics
Adds Google Analytics tracking code to your WordPress site. Supports many tracking features.
PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin
pretty-link
🌠 The best WordPress link management, branding, tracking, sharing and payments plugin. Easily make pretty & trackable shortlinks. 🔗
Simple History – Track, Log, and Audit WordPress Changes
simple-history
Track changes and user activities on your WordPress site. See who created a page, uploaded an attachment, and more, for a complete audit trail.
WH Tweaks Developer Profile
6 plugins · 95K total installs
How We Detect WH Tweaks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wh-tweaks/css/public.css/wp-content/plugins/wh-tweaks/css/admin.css/wp-content/plugins/wh-tweaks/js/public.js/wp-content/plugins/wh-tweaks/js/admin.js/wp-content/plugins/wh-tweaks/js/public.js/wp-content/plugins/wh-tweaks/js/admin.jswh-tweaks/css/public.css?ver=wh-tweaks/css/admin.css?ver=wh-tweaks/js/public.js?ver=wh-tweaks/js/admin.js?ver=HTML / DOM Fingerprints
wht-video-containerdata-wht-modalwht_settings/wp-json/wh-tweaks/v1/settings[year][date]