
WP-PluginsUsed Security & Risk Analysis
wordpress.org/plugins/wp-pluginsusedDisplay WordPress plugins that you currently have (both active and inactive) onto a post/page.
Is WP-PluginsUsed Safe to Use in 2026?
Generally Safe
Score 85/100WP-PluginsUsed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-pluginsused" plugin v1.50.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are all positive indicators. Furthermore, the plugin's attack surface is limited to three shortcodes, and critically, none of these entry points are identified as unprotected. The taint analysis also shows no critical or high-severity flows, which is a significant strength.
However, there are a few areas that warrant attention. The plugin does not implement nonce checks or capability checks on its entry points. While the current attack surface is small and no immediate vulnerabilities are apparent in the static analysis, the lack of these fundamental security checks means that if the plugin's functionality were to evolve and expose more sensitive operations or data, it could become susceptible to certain types of attacks without proper authorization enforcement. The vulnerability history is clean, with no recorded CVEs, which is a positive sign of its past security performance.
In conclusion, "wp-pluginsused" v1.50.2 appears to be a securely coded plugin in its current state, with no critical or high-risk issues identified in the static analysis or vulnerability history. The primary concern lies in the absence of nonce and capability checks, which represents a potential future risk if the plugin's attack surface or functionality expands. The plugin's developers have demonstrated good practices in other areas, suggesting a commitment to security, but this oversight should be addressed for robust, long-term security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Potential for unsanitized output
WP-PluginsUsed Security Vulnerabilities
WP-PluginsUsed Release Timeline
WP-PluginsUsed Code Analysis
Output Escaping
WP-PluginsUsed Attack Surface
Shortcodes 3
WordPress Hooks 1
Maintenance & Trust
WP-PluginsUsed Maintenance & Trust
Maintenance Signals
Community Trust
WP-PluginsUsed Alternatives
Shortcodes Analyzer
shortcodes-analyzer
Scan your entire WordPress site in one click to find exactly where every shortcode is used across posts, pages, and custom post types.
Plugins Garbage Collector (Database Cleanup)
plugins-garbage-collector
Find unused database tables from deactivated or deleted plugins. You can delete unused database tables to reduce database volume and enhance site perf …
WP Sort Order
wp-sort-order
Order terms (Users, Posts, Pages, Custom Post Types and Custom Taxonomies) using a Drag and Drop with jQuery ui Sortable.
Media Hygiene: Remove or Delete Unused Images and More!
media-hygiene
The Media Hygiene plugin removes unused media from the WordPress library to free up space, reduce clutter, and improve server performance.
Shortcodes Finder
shortcodes-finder
Shortcodes Finder helps you to find, test, clean and get informations about the shortcodes in your WordPress website posts, pages and custom contents.
WP-PluginsUsed Developer Profile
20 plugins · 888K total installs
How We Detect WP-PluginsUsed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-pluginsused/images/plugin_active.gif/wp-content/plugins/wp-pluginsused/images/plugin_inactive.gifHTML / DOM Fingerprints
[pluginsused][pluginsused type='active'][pluginsused type='inactive'][pluginsused type='stats']