WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login Security & Risk Analysis

wordpress.org/plugins/wphhsecure

Secure your WordPress site with one-click file locking, login path hiding, role-based access, and smart dashboard visibility.

70 active installs v1.1.9 PHP + WP 5.0+ Updated Jan 21, 2026
brute-force-protectionfile-lockinghide-login-urlwordpress-securitywp-filesystem
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login Safe to Use in 2026?

Generally Safe

Score 100/100

WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "wphhsecure" v1.1.9 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, employing prepared statements for all SQL queries, and ensuring all output is properly escaped. The absence of known vulnerabilities in its history is also a strong indicator of a well-maintained and secure codebase. However, a significant concern lies within its attack surface. The plugin exposes eight AJAX handlers, with a concerning seven of them lacking any authentication checks. This wide exposure of unprotected entry points presents a substantial risk of unauthorized access and potential exploitation, even in the absence of known critical taint flows or direct SQL injection vulnerabilities. The single taint flow identified with unsanitized paths, while not classified as critical or high, warrants attention as it could potentially lead to unexpected behavior or vulnerabilities if exploited under specific conditions. In conclusion, while the plugin's internal code hygiene is commendable, the lack of proper authentication on a majority of its AJAX handlers is a critical weakness that significantly elevates its risk profile and requires immediate remediation.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
Vulnerabilities
None known

WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
3
Capability Checks
3
File Operations
6
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<hide-wp-url> (templates\hide-wp-url.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login Attack Surface

Entry Points8
Unprotected7

AJAX Handlers 8

authwp_ajax_wphhsecure_get_excluded_foldersincludes\ajax-handlers.php:5
authwp_ajax_wphhsecure_add_excluded_folderincludes\ajax-handlers.php:18
authwp_ajax_wphhsecure_remove_folderincludes\ajax-handlers.php:45
authwp_ajax_wphhsecure_reset_permissionsincludes\ajax-handlers.php:72
authwp_ajax_wphhsecure_check_batchesincludes\ajax-handlers.php:82
authwp_ajax_wphhsecure_check_locking_statusincludes\ajax-handlers.php:95
authwp_ajax_wphhsecure_get_lock_statusincludes\ajax-handlers.php:120
authwp_ajax_wphhsecure_change_permissionsincludes\class-wphhsecure.php:12
WordPress Hooks 9
actionadmin_enqueue_scriptsincludes\admin-notices.php:4
actionadmin_noticesincludes\admin-notices.php:29
actionadmin_noticesincludes\class-hide-wp-url-handler.php:9
actioninitincludes\class-hide-wp-url-handler.php:10
actionwp_logoutincludes\class-hide-wp-url-handler.php:96
actionwphhsecure_process_filesincludes\class-permission-manager.php:324
actionadmin_menuincludes\class-wphhsecure.php:9
actionplugins_loadedwphhsecure.php:37
actionadmin_enqueue_scriptswphhsecure.php:102

Scheduled Events 1

wphhsecure_process_files
Maintenance & Trust

WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings7
Active installs70
Developer Profile

WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login Developer Profile

WPHackedHelp

1 plugin · 70 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wphhsecure/css/style.css/wp-content/plugins/wphhsecure/js/wphhsecure.js/wp-content/plugins/wphhsecure/js/wphhsecure-status.js

HTML / DOM Fingerprints

CSS Classes
wphhsecure-dynamic-notice
JS Globals
WPHHSecure
FAQ

Frequently Asked Questions about WPHH SECURE – AIO WordPress Security With File Locking & WP Hide Login