
WP Cleanup and base Functions Security & Risk Analysis
wordpress.org/plugins/wp-clean-up-deoHere is a short description of the plugin. This should be no more than 150 characters. No markup here.
Is WP Cleanup and base Functions Safe to Use in 2026?
Generally Safe
Score 85/100WP Cleanup and base Functions has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-clean-up-deo" v1.0.0 plugin exhibits a generally positive security posture based on the provided static analysis. It successfully avoids dangerous functions and all SQL queries are properly prepared, mitigating risks of SQL injection. The absence of external HTTP requests and a taint analysis showing no unsanitized paths further contributes to its good standing.
However, there are notable areas for improvement. A significant concern is the low rate of proper output escaping (20%), which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sanitized before being displayed. The plugin also lacks nonce checks and capability checks, which are crucial for securing entry points, even though the current attack surface is small and appears to have no unprotected entry points. The vulnerability history is clean, which is a strong positive indicator, but the lack of historical data makes it difficult to assess long-term security trends.
In conclusion, while the plugin demonstrates strengths in its handling of SQL and avoidance of common dangerous functions, the insufficient output escaping and absence of critical security checks like nonces and capabilities represent potential weaknesses that need to be addressed to achieve a robust security profile.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
WP Cleanup and base Functions Security Vulnerabilities
WP Cleanup and base Functions Release Timeline
WP Cleanup and base Functions Code Analysis
Output Escaping
WP Cleanup and base Functions Attack Surface
Shortcodes 2
WordPress Hooks 17
Maintenance & Trust
WP Cleanup and base Functions Maintenance & Trust
Maintenance Signals
Community Trust
WP Cleanup and base Functions Alternatives
WP-Sweep
wp-sweep
WP-Sweep allows you to clean up unused, orphaned and duplicated data in your WordPress. It also optimizes your database tables.
Optimize Database after Deleting Revisions
rvg-optimize-database
One-click database optimization with precise revision cleanup and flexible scheduling. Speeding up sites since 2011!
Delete Duplicate Posts
delete-duplicate-posts
Get rid of duplicate posts and pages (any post type) on your blog with manual or automatic modes.
Disable Bloat for WordPress & WooCommerce
disable-dashboard-for-woocommerce
All-in-One solution to speed up your WordPress & WooCommerce. Remove unnecessary features and make your site faster and cleaner.
Simple Revisions Delete
simple-revisions-delete
Simple Revisions Delete adds a discreet link within a post submit box to let you purge (delete) its revisions via AJAX. Bulk actions also available.
WP Cleanup and base Functions Developer Profile
1 plugin · 10 total installs
How We Detect WP Cleanup and base Functions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-cbf/admin/css/wp-cbf-admin.css/wp-content/plugins/wp-cbf/admin/js/wp-cbf-admin.jswp-content/plugins/wp-cbf/admin/js/wp-cbf-admin.jswp-cbf/admin/css/wp-cbf-admin.css?ver=wp-cbf/admin/js/wp-cbf-admin.js?ver=HTML / DOM Fingerprints
<!-- Plugin Name: WP Cleanup and base Functions -->