
WP safely disable directory browsing Security & Risk Analysis
wordpress.org/plugins/wp-safely-disable-directory-browsingThis essential .htaccess rules plugin allow you to improve security of your wordpress blog.
Is WP safely disable directory browsing Safe to Use in 2026?
Generally Safe
Score 85/100WP safely disable directory browsing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-safely-disable-directory-browsing" plugin version 0.1 presents a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and the static analysis shows a very small attack surface with no obvious entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected. Furthermore, all SQL queries are properly prepared, which is a strong security practice. However, significant concerns arise from the output escaping and file operation analysis. Zero percent of its total outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis reveals two flows with unsanitized paths, and while no critical or high severity issues were flagged directly, unsanitized paths are a common precursor to more severe vulnerabilities. The absence of nonce checks and capability checks on any potential (though seemingly nonexistent) entry points is also a notable weakness.
While the plugin's vulnerability history is clean, this could be due to its age, minimal usage, or simply the lack of deep security audits. The presence of unsanitized paths coupled with unescaped output creates a significant risk for XSS attacks. The plugin's stated purpose is to disable directory browsing, which is a security feature itself, but its implementation appears to introduce other security weaknesses. Overall, the plugin demonstrates a basic understanding of SQL security but fails significantly in output sanitization and path handling, making it a moderate to high risk for XSS and potential path traversal if any unintended entry points were to be discovered.
Key Concerns
- Unescaped output detected
- Flows with unsanitized paths detected
- No nonce checks implemented
- No capability checks implemented
WP safely disable directory browsing Security Vulnerabilities
WP safely disable directory browsing Code Analysis
Output Escaping
Data Flow Analysis
WP safely disable directory browsing Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP safely disable directory browsing Maintenance & Trust
Maintenance Signals
Community Trust
WP safely disable directory browsing Alternatives
WP Super Secure and Fast htaccess
wp-super-secure-and-fast-htaccess
This essential .htaccess rules plugin allow you to improve security and speed of your wordpress blog.
Redirection
redirection
Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.
MalCare WordPress Security Plugin – Malware Scanner, Cleaner, Security Firewall
malcare-security
Get Bulletproof Security for your WordPress site. WordPress security plugin packed with comprehensive Firewall, malware scanner, cleaner & more.
SecuPress with Simple SSL – Simple and Performant Security
secupress
Protect your WordPress with SecuPress, analyze and ensure the safety of your website daily.
Htaccess File Editor – Safely Edit Htaccess File
wp-htaccess-editor
A safe & simple htaccess file editor with automatic htaccess backups & htaccess file syntax testing.
WP safely disable directory browsing Developer Profile
1 plugin · 300 total installs
How We Detect WP safely disable directory browsing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
sm-paddedid="sm_div"