WP Frame Breaker Security & Risk Analysis

wordpress.org/plugins/wp-frame-breaker

Adds a short javascript to your blog header to break out of any containing frames

30 active installs v1.0 PHP + WP 2.3+ Updated Apr 13, 2009
breakdiggframesremove
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Frame Breaker Safe to Use in 2026?

Generally Safe

Score 85/100

WP Frame Breaker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The 'wp-frame-breaker' v1.0 plugin exhibits an exceptionally strong security posture based on the provided static analysis. The complete absence of any identified attack surface, dangerous functions, direct SQL queries, unescaped output, file operations, external HTTP requests, and crucially, nonce or capability checks, suggests a very minimal and secure codebase. The taint analysis further reinforces this, showing zero flows with unsanitized paths. This indicates a robust implementation that avoids common web vulnerabilities.

The plugin's vulnerability history is also entirely clean, with no recorded CVEs, indicating a history of secure development or timely patching by maintainers. The plugin appears to adhere to best practices by not exposing unnecessary entry points and by likely relying on WordPress's core security features for any interactions.

While the absence of any detected issues is highly positive, it's worth noting that a zero attack surface in a plugin could sometimes indicate that the plugin's functionality is either extremely limited or that the analysis might have missed certain indirect entry points. However, based strictly on the provided data, the plugin is assessed as having a very low risk profile.

Vulnerabilities
None known

WP Frame Breaker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Frame Breaker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP Frame Breaker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_headwp-frame-breaker.php:30
actionplugins_loadedwp-frame-breaker.php:48
Maintenance & Trust

WP Frame Breaker Maintenance & Trust

Maintenance Signals

WordPress version tested2.7.1
Last updatedApr 13, 2009
PHP min version
Downloads9K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

WP Frame Breaker Developer Profile

paulmac

4 plugins · 80 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Frame Breaker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- Start WP Frame Breaker Script --><!-- End WP Frame Breaker Script -->
FAQ

Frequently Asked Questions about WP Frame Breaker