WPLauncher – Simple Development Requests Security & Risk Analysis

wordpress.org/plugins/wplauncher

Simple way to request development work for your website.

0 active installs v1.0.0 PHP 5.2.4+ WP 3.0.1+ Updated Jun 11, 2019
developmentdevelopment-requestsexpert-web-developmentrequest-development-worktickets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPLauncher – Simple Development Requests Safe to Use in 2026?

Generally Safe

Score 85/100

WPLauncher – Simple Development Requests has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of wplauncher v1.0.0 reveals a generally positive security posture, with no identified dangerous functions, SQL queries using prepared statements, or file operations. The absence of external HTTP requests and bundled libraries is also a strong indicator of good security practices. Furthermore, the plugin demonstrates a commitment to security by including both nonce and capability checks, which are crucial for protecting against common WordPress vulnerabilities. The complete lack of known CVEs and a clean vulnerability history further bolster this positive assessment, suggesting that the developers are either highly diligent or the plugin has not yet been a target for sophisticated attacks.

However, a significant concern arises from the output escaping analysis. With only 47% of outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any data that is not properly escaped when displayed to users could potentially be manipulated by attackers to inject malicious scripts. While the attack surface appears minimal with no exposed AJAX handlers, REST API routes, or shortcodes without authentication, the unescaped output represents a tangible and potentially exploitable weakness that warrants immediate attention. The plugin's minimal attack surface and strong history are commendable, but the output escaping issue introduces a critical area of concern that could undermine its overall security.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

WPLauncher – Simple Development Requests Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WPLauncher – Simple Development Requests Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

WPLauncher – Simple Development Requests Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
18 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

47% escaped38 total outputs
Attack Surface

WPLauncher – Simple Development Requests Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actioninitadmin\class-wplauncher-admin.php:54
actionadd_meta_boxes_wplauncher_requestsadmin\class-wplauncher-admin.php:55
actionsave_post_wplauncher_requestsadmin\class-wplauncher-admin.php:56
actionadmin_menuadmin\class-wplauncher-admin.php:59
actionadmin_initadmin\class-wplauncher-admin.php:61
filterpost_updated_messagesadmin\class-wplauncher-admin.php:62
filtermanage_wplauncher_requests_posts_columnsadmin\class-wplauncher-admin.php:65
actionmanage_wplauncher_requests_posts_custom_columnadmin\class-wplauncher-admin.php:67
actionadmin_noticesadmin\class-wplauncher-admin.php:581
actionplugins_loadedincludes\class-wplauncher.php:142
actionadmin_enqueue_scriptsincludes\class-wplauncher.php:157
actionadmin_enqueue_scriptsincludes\class-wplauncher.php:158
actionwp_enqueue_scriptsincludes\class-wplauncher.php:173
actionwp_enqueue_scriptsincludes\class-wplauncher.php:174
Maintenance & Trust

WPLauncher – Simple Development Requests Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 11, 2019
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WPLauncher – Simple Development Requests Developer Profile

Ben Shadle

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPLauncher – Simple Development Requests

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wplauncher/admin/css/wplauncher-admin.css/wp-content/plugins/wplauncher/admin/js/wplauncher-admin.js
Script Paths
/wp-content/plugins/wplauncher/admin/js/wplauncher-admin.js
Version Parameters
wplauncher-admin.css?ver=wplauncher-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WPLauncher – Simple Development Requests