
Word Replacer Security & Risk Analysis
wordpress.org/plugins/word-replacerReplace word by another word in post, page, or comment. And... bbPress
Is Word Replacer Safe to Use in 2026?
Generally Safe
Score 85/100Word Replacer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'word-replacer' plugin v0.4 exhibits a generally good security posture with no recorded vulnerabilities in its history and a limited attack surface. The static analysis reveals no critical code signals like dangerous functions, file operations, or external HTTP requests, and importantly, no unsanitized taint flows. The absence of known CVEs also contributes positively to its security. However, there are areas for improvement. The plugin utilizes prepared statements for only 40% of its SQL queries, indicating a potential risk of SQL injection if not handled with extreme care in the remaining queries. Furthermore, only 15% of output is properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of a single nonce check is a positive sign, but the complete lack of capability checks for its entry points, although currently zero, means any future additions without proper authorization checks would be immediately exploitable.
Key Concerns
- Low percentage of properly escaped output
- SQL queries not consistently using prepared statements
- No capability checks on entry points
Word Replacer Security Vulnerabilities
Word Replacer Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Word Replacer Attack Surface
WordPress Hooks 8
Maintenance & Trust
Word Replacer Maintenance & Trust
Maintenance Signals
Community Trust
Word Replacer Alternatives
No Page Comment
no-page-comment
An admin interface to control the default comment and trackback settings on new posts, pages and custom post types.
Search and Replace
search-replace
Search and replace content into pages and posts
Remove noreferrer
remove-noreferrer
"Remove noreferrer" automatically removes rel="noreferrer" attribute from links on your website on-the-fly.
Disable Feeds and Comments
disable-rss-feeds-and-comments
This WordPress plugin, "Disable RSS Feeds and Comments," gives you the ability to turn off both the RSS feeds and comments on pages and/or p …
WP Find And Replace
wp-find-and-replace
Find and replace content into pages and posts
Word Replacer Developer Profile
6 plugins · 1K total installs
How We Detect Word Replacer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/word-replacer/word-replacer.phpHTML / DOM Fingerprints
strip_backslashreplacer_expandablename='delete[]'name='id[]'name='count'name='original[]'name='replacement[]'name='in_posts[]'+8 morejQuery