
WP Whoosh Security & Risk Analysis
wordpress.org/plugins/wp-whooshBuild new feature-rich, fast and secure WordPress sites in a smarter way in under 60 seconds using WP Whoosh.
Is WP Whoosh Safe to Use in 2026?
Generally Safe
Score 85/100WP Whoosh has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-whoosh plugin v1.6 exhibits a generally good security posture, with no publicly known vulnerabilities (CVEs) and a clean vulnerability history. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface, and all detected SQL queries use prepared statements, which is excellent. However, the presence of 'unserialize' as a dangerous function, coupled with two flows with unsanitized paths, raises concerns. While no critical or high severity issues were found in the taint analysis, these could still be exploited under specific conditions. The low percentage of properly escaped output (28%) indicates a weakness that could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully.
Key Concerns
- Dangerous function 'unserialize' found
- Flows with unsanitized paths detected
- Low percentage of properly escaped output
WP Whoosh Security Vulnerabilities
WP Whoosh Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
WP Whoosh Attack Surface
WordPress Hooks 38
Maintenance & Trust
WP Whoosh Maintenance & Trust
Maintenance Signals
Community Trust
WP Whoosh Alternatives
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
Simply Static – The Static Site Generator
simply-static
Convert WordPress to static HTML. Boost performance 3-5x. Eliminate security vulnerabilities. Deploy anywhere.
Plugin Check (PCP)
plugin-check
Plugin Check is a WordPress.org tool which provides checks to help plugins meet the directory requirements and follow various best practices.
DefendWP Firewall
defend-wp-firewall
Get instant protection against vulnerabilities disclosed by security companies.
WP Whoosh Developer Profile
4 plugins · 4K total installs
How We Detect WP Whoosh
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-whoosh/admin.csswp-whoosh/admin.css?ver=HTML / DOM Fingerprints
<!-- Admin page --><!-- Intro tab -->data-template-urldata-key-urldata-secret-urldata-hosts-urldata-sites-urldata-credits-url