
WP Don't GO Security & Risk Analysis
wordpress.org/plugins/wp-dont-goThis plug-in changes the tab title and favicon when your visitors skip to another tab.
Is WP Don't GO Safe to Use in 2026?
Generally Safe
Score 85/100WP Don't GO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-dont-go plugin v1.1 exhibits a generally good security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a minimal attack surface with no unprotected entry points. The absence of dangerous functions, raw SQL queries, and file operations is also a positive indicator. However, a concerning finding is that only 43% of output is properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sufficient sanitization. While the plugin makes one external HTTP request, the analysis does not specify if this is a security concern. The presence of one nonce check is noted, but the absence of capability checks on any entry points could be a weakness if such entry points were discovered. The vulnerability history is clean, with no known CVEs, suggesting a history of secure development or a lack of prior focused security scrutiny. Overall, the plugin's strengths lie in its small attack surface and lack of risky code patterns, but the unescaped output is a significant concern that requires attention to prevent potential client-side attacks.
Key Concerns
- Low percentage of properly escaped output
- No capability checks on entry points
WP Don't GO Security Vulnerabilities
WP Don't GO Release Timeline
WP Don't GO Code Analysis
Output Escaping
Data Flow Analysis
WP Don't GO Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP Don't GO Maintenance & Trust
Maintenance Signals
Community Trust
WP Don't GO Alternatives
No alternatives data available yet.
WP Don't GO Developer Profile
8 plugins · 80 total installs
How We Detect WP Don't GO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-dont-go/assets/css/wpajansPanel.css/wp-content/plugins/wp-dont-go/assets/js/wpajansPlugin.js/wp-content/plugins/wp-dont-go/assets/js/dontgo.js/wp-content/plugins/wp-dont-go/assets/js/wpajansPlugin.js/wp-content/plugins/wp-dont-go/assets/js/dontgo.jswp-dont-go/assets/css/wpajansPanel.css?ver=wp-dont-go/assets/js/wpajansPlugin.js?ver=wp-dont-go/assets/js/dontgo.js?ver=HTML / DOM Fingerprints
wpajansNoticewpajansInputwpnlh_navbarwpnlh_contentwpnlh_content_blockwpajansLogo<!-- Plugin CODES --><!-- #Plugin CODES -->data-nonce_fielddata-nonce_actiondontgoSettings