Remove Unwanted Subscribers Security & Risk Analysis

wordpress.org/plugins/withinweb-remove-spam-subscribers

Remove unwanted users automatically using a CRON Job.

20 active installs v1.0.7 PHP + WP 3.0.1+ Updated Dec 7, 2019
cron-jobremove-subscribersspam-subscribersspam-userssubscribers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Remove Unwanted Subscribers Safe to Use in 2026?

Generally Safe

Score 85/100

Remove Unwanted Subscribers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The withinweb-remove-spam-subscribers plugin version 1.0.7 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, proper usage of prepared statements for all SQL queries, and 100% output escaping significantly reduce the risk of common web vulnerabilities like SQL injection and XSS. The presence of nonce and capability checks, while limited in scope due to a small attack surface, indicates a foundational understanding of WordPress security best practices.

However, the static analysis reveals a minimal attack surface with 0 AJAX handlers, 0 REST API routes, and 0 shortcodes. This could indicate that the plugin's functionality is very limited or relies entirely on its single cron event. While no specific vulnerabilities were identified in the code analysis or taint flows, and there is no known vulnerability history, the lack of observable entry points other than a cron event makes it difficult to comprehensively assess its security. The absence of external HTTP requests and file operations further limits potential attack vectors originating from the plugin itself.

In conclusion, the plugin appears to be well-secured against common threats based on the provided data, exhibiting good coding practices. The limited attack surface and lack of known vulnerabilities are positive indicators. The primary concern is the limited scope of analysis due to the minimal exposed functionality. Without more interaction points, it's hard to definitively rule out all potential issues, but the current evidence suggests a low risk profile.

Vulnerabilities
None known

Remove Unwanted Subscribers Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Remove Unwanted Subscribers Release Timeline

v1.0.7Current
v1.0.6
v1.0.5
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Remove Unwanted Subscribers Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
0
9 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

100% escaped9 total outputs
Attack Surface

Remove Unwanted Subscribers Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuwithinweb_wwrs_remove_subscribers.php:25
actionadmin_post_withinweb_wwrs_settingswithinweb_wwrs_remove_subscribers.php:30
actionwithinweb_wwrs_cron_hookwithinweb_wwrs_remove_subscribers.php:91

Scheduled Events 1

withinweb_wwrs_cron_hook
Maintenance & Trust

Remove Unwanted Subscribers Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedDec 7, 2019
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Remove Unwanted Subscribers Developer Profile

paulvgibbs

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Remove Unwanted Subscribers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/withinweb-remove-spam-subscribers/scripts/process.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Remove Unwanted Subscribers