
WP-HideRefer Security & Risk Analysis
wordpress.org/plugins/wp-hidereferWP-HideRefer adds proxies to your outgoing links, keeping your site private!
Is WP-HideRefer Safe to Use in 2026?
Generally Safe
Score 85/100WP-HideRefer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-hiderefer" v1.12 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of identified dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are strong indicators of good development practices. Furthermore, the lack of any recorded vulnerabilities in its history suggests a history of secure development.
However, there are areas for improvement. The analysis reveals that only 40% of output is properly escaped, which presents a potential risk for cross-site scripting (XSS) vulnerabilities if sensitive data is not handled carefully. While the attack surface appears minimal with 0 entry points, the lack of nonce and capability checks on any potential, albeit currently non-existent, entry points is a notable oversight. In the absence of identified vulnerabilities, the current risk is low, but these coding practices could introduce risks in future updates if not addressed.
Key Concerns
- Output escaping is insufficient
- No nonce checks on entry points
- No capability checks on entry points
WP-HideRefer Security Vulnerabilities
WP-HideRefer Code Analysis
SQL Query Safety
Output Escaping
WP-HideRefer Attack Surface
WordPress Hooks 9
Maintenance & Trust
WP-HideRefer Maintenance & Trust
Maintenance Signals
Community Trust
WP-HideRefer Alternatives
WP Migrate DB Anonymization
wp-migrate-db-anonymization
Addon for WP Migrate DB and WP Migrate DB Pro to anonymize user data on database export, pull or push.
Contact Form 7 – Phone mask field
cf7-phone-mask-field
This plugin adds a new field in which you can set the phone number mask or other to Contact Form 7.
Input Mask For Elementor Form Fields
mask-form-elementor
Apply input masks in Elementor form widget fields - phone, date, time, credit card, CPF, CNPJ, CEP & more for valid and error-free entries.
Form Input Masks For Elementor Forms
form-masks-for-elementor
Add input masks to Elementor Pro or Hello Plus form fields - phone, date, time, credit card, CPF, CNPJ, CEP & more for accurate entries.
Masks Form Fields
masks-form-fields
A plugin to add masks in the form’s fields.
WP-HideRefer Developer Profile
6 plugins · 5K total installs
How We Detect WP-HideRefer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.