
Who Delete My Posts Security & Risk Analysis
wordpress.org/plugins/who-delete-my-postsRecord who, when and what post or page is deleted in your wordpress site.
Is Who Delete My Posts Safe to Use in 2026?
Generally Safe
Score 85/100Who Delete My Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "who-delete-my-posts" plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the potential attack surface. Furthermore, the code signals are positive, with no dangerous functions detected, all output being properly escaped, and no file operations or external HTTP requests. The SQL query usage, while not 100% prepared, shows a majority of queries employing prepared statements, which is a good practice.
However, a significant concern arises from the complete absence of nonce checks and capability checks. While the current entry points are limited, any future expansion of the plugin's functionality without these essential security measures could introduce vulnerabilities. The taint analysis showing zero flows is also a positive indicator, suggesting no immediate cross-site scripting (XSS) or other injection vulnerabilities. The plugin's history of zero known CVEs further reinforces its current perceived security, indicating a responsible development approach thus far.
In conclusion, the plugin is currently in a secure state with minimal attack surface and good coding practices in place. The primary weakness lies in the lack of fundamental security checks like nonces and capability checks, which represent a potential risk if the plugin's functionality expands or if unforeseen vulnerabilities are introduced through future updates. Addressing these checks would further solidify its security.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- SQL queries not using prepared statements (33% of total)
Who Delete My Posts Security Vulnerabilities
Who Delete My Posts Code Analysis
SQL Query Safety
Output Escaping
Who Delete My Posts Attack Surface
WordPress Hooks 3
Maintenance & Trust
Who Delete My Posts Maintenance & Trust
Maintenance Signals
Community Trust
Who Delete My Posts Alternatives
Wordfence Security – Firewall, Malware Scan, and Login Security
wordfence
Firewall, Malware Scanner, Two Factor Auth, and Comprehensive Security Features, powered by our 24-hour team. Make security a priority with Wordfence.
Hostinger Tools
hostinger
Simplified WordPress management. Manage site info, maintenance, security, & redirects.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
Really Simple Security – Simple and Performant Security (formerly Really Simple SSL)
really-simple-ssl
Easily improve site security with WordPress Hardening, Two-Factor Authentication (2FA), Login Protection, Vulnerability Detection and SSL certificate.
Limit Login Attempts Reloaded – Login Security, Brute Force Protection, Firewall
limit-login-attempts-reloaded
Block excessive login attempts and protect your site against brute force attacks. Simple, yet powerful tools to improve site performance.
Who Delete My Posts Developer Profile
5 plugins · 140 total installs
How We Detect Who Delete My Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/who-delete-my-posts/assets/css/bootstrap.min.css/wp-content/plugins/who-delete-my-posts/assets/css/bootstrap-icon.css/wp-content/plugins/who-delete-my-posts/assets/css/style.css/wp-content/plugins/who-delete-my-posts/assets/js/bootstrap.bundle.min.js/wp-content/plugins/who-delete-my-posts/assets/js/script.js/wp-content/plugins/who-delete-my-posts/assets/js/script.jswho-delete-my-posts/assets/css/style.css?ver=who-delete-my-posts/assets/js/script.js?ver=HTML / DOM Fingerprints
whodeletemyposts-settingsdata-bs-toggledata-bs-targetWhodeleteapp