WP Offline Browser Security & Risk Analysis

wordpress.org/plugins/wp-offline-browser

Super offline browser for wordpress.

10 active installs v1.0 PHP + WP 2.8+ Updated Jan 5, 2014
cache-manifestcache-pluginwp-cachewp-offline-browser
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Offline Browser Safe to Use in 2026?

Generally Safe

Score 85/100

WP Offline Browser has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "wp-offline-browser" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all outputs are properly escaped. The plugin also has a clean vulnerability history with zero recorded CVEs. The absence of external HTTP requests and a seemingly zero attack surface (no AJAX handlers, REST API routes, shortcodes, or cron events) are positive indicators. However, the complete lack of nonce and capability checks, coupled with the presence of file operations without any visible input validation or sanitization indicated by the taint analysis, raises concerns. While no specific vulnerabilities were detected in this static analysis, the absence of these fundamental security mechanisms means that if any entry point were to be discovered or introduced, it could be highly susceptible to exploitation.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Presence of file operations without taint analysis
Vulnerabilities
None known

WP Offline Browser Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Offline Browser Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
0
Bundled Libraries
0
Attack Surface

WP Offline Browser Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterlanguage_attributeswp-offline-browser.php:25
filtermod_rewrite_ruleswp-offline-browser.php:26
actionadmin_menuwp-offline-browser.php:39
Maintenance & Trust

WP Offline Browser Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJan 5, 2014
PHP min version
Downloads3K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

WP Offline Browser Developer Profile

Anop Goswami

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Offline Browser

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-offline-browser/includes/updater.js
Script Paths
includes/updater.js

HTML / DOM Fingerprints

CSS Classes
wrap
FAQ

Frequently Asked Questions about WP Offline Browser