Wp Hide Add New Theme Security & Risk Analysis

wordpress.org/plugins/wp-hide-add-new-theme

This plugin will disable the functionalities of add new themes, plugins and file editing in your WordPress dashboard. If someone access your backend h …

0 active installs v1.0 PHP + WP 5.0+ Updated Feb 23, 2019
admindisablehide-add-new-themepluginswp-admin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wp Hide Add New Theme Safe to Use in 2026?

Generally Safe

Score 85/100

Wp Hide Add New Theme has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The static analysis of wp-hide-add-new-theme v1.0 reveals a plugin with a seemingly minimal attack surface, as it reports zero AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code signals indicate no dangerous functions, all SQL queries use prepared statements, and all outputs are properly escaped, which are positive security practices. The absence of external HTTP requests and file operations also contributes to a reduced risk profile. The plugin also has no recorded vulnerability history, suggesting a history of stability or limited exposure.

However, the analysis also highlights a significant concern: a complete lack of nonce checks and capability checks. This indicates that any potential entry points, even if currently non-existent or implicitly handled by WordPress core, are not being secured at the plugin level. While the current attack surface is reported as zero, this absence of crucial security checks presents a latent risk. If future updates introduce any form of user-interactive functionality without implementing these checks, it could lead to significant vulnerabilities.

In conclusion, wp-hide-add-new-theme v1.0 demonstrates good practices in its current implementation regarding SQL and output handling. However, the complete omission of nonce and capability checks is a notable weakness. While the plugin currently presents a low risk due to its limited attack surface, this architectural oversight means it is not inherently secure and could become vulnerable with future modifications or if WordPress core behavior changes affect its implicit handling.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Wp Hide Add New Theme Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Wp Hide Add New Theme Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Wp Hide Add New Theme Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Wp Hide Add New Theme Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedFeb 23, 2019
PHP min version
Downloads951

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Wp Hide Add New Theme Developer Profile

Ismail Ashraf

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wp Hide Add New Theme

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-hide-add-new-theme/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Wp Hide Add New Theme