
WP Revisions Manager Security & Risk Analysis
wordpress.org/plugins/wp-revisions-managerWP Revisions Manager let you purge (delete) its revisions via AJAX. There is also a Bulk action in the post lists. You can also limit the number of re …
Is WP Revisions Manager Safe to Use in 2026?
Generally Safe
Score 85/100WP Revisions Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wp-revisions-manager' v1.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities (CVEs) in its history and the presence of nonce and capability checks on all identified entry points (AJAX handlers) are positive indicators. Furthermore, the code signals reveal that all SQL queries are using prepared statements, and there are no file operations or external HTTP requests, all of which significantly reduce common attack vectors.
However, a key concern arises from the output escaping. With 13 total outputs, only 38% are properly escaped. This suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities. While the current taint analysis shows no unsanitized flows, this could be due to the limited scope of the analysis or the specific code paths examined. The lack of any recorded vulnerabilities in its history is positive but does not entirely negate the potential for undiscovered issues, especially given the incomplete output escaping.
Key Concerns
- Insufficient output escaping
WP Revisions Manager Security Vulnerabilities
WP Revisions Manager Code Analysis
Output Escaping
WP Revisions Manager Attack Surface
AJAX Handlers 3
WordPress Hooks 19
Maintenance & Trust
WP Revisions Manager Maintenance & Trust
Maintenance Signals
Community Trust
WP Revisions Manager Developer Profile
6 plugins · 12K total installs
How We Detect WP Revisions Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-revisions-manager/js/wprm-script.js/wp-content/plugins/wp-revisions-manager/js/wprm-script.jswprm-script.js?ver=HTML / DOM Fingerprints
wprd-btndata-post-iddata-actiondata-noncewprevisionmanager