WPDeeply
Download free plugin

Plugin Security

How to judge, replace and remove WordPress plugins.

40
Guides
How Long Is Too Long Without a Plugin Update? What update gaps actually predict, and the thresholds WPDeeply uses. Plugin Security 11 Jun 2026, 2 min How to Replace an Abandoned WordPress Plugin A migration order that avoids losing data or breaking a live site. Plugin Security 29 May 2026, 2 min Should You Delete Inactive WordPress Plugins? Deactivated is not the same as gone. What an inactive plugin can and cannot do. Plugin Security 17 Apr 2026, 2 min How to Check If a WordPress Plugin Is Safe Five checks, in order of usefulness, before you install a WordPress plugin. Plugin Security 4 Mar 2026, 2 min A Plugin Was Removed From WordPress.org. What Does That Mean? Closed, removed, or just gone — how to read a missing plugin listing, and what to do. Plugin Security 20 Feb 2026, 2 min WP Job Manager Permission Escalation to RCE: Risk Profile and Response Permission escalation is dangerous because it changes who can perform sensitive actions. On a WordPress site, that can quickly become plugin installation, file writes, or code execution. Plugin Security 25 Nov 2020, 2 min WordPress Protected Meta Exposure via WP Job Manager: What Site Owners Should Know Protected meta is only protected if every plugin respects the boundary. Job, listing, and directory plugins often attach sensitive operational data to posts, so permission checks matter. Plugin Security 11 Aug 2020, 2 min LearnPress SQL Injection to RCE: Lessons for WordPress LMS Sites LMS plugins hold users, progress, payments, certificates, and admin workflows. A SQL injection in that environment can become more than a data leak if chained with privileged actions. Plugin Security 20 Jul 2020, 2 min WooCommerce MySQL REPLACE to RCE: Why Store Plugins Need Fast Patching WooCommerce runs close to money and customer data. Any chain that moves from database manipulation toward code execution should be treated as an emergency, even if exploitation requires… Plugin Security 18 Jul 2020, 2 min WordPress Importer and _wp_attached_file: Why Imports Need Security Review Importers create content and file references from external data. If the importer trusts attachment metadata too much, a migration file can become a security boundary problem. Plugin Security 17 Jul 2020, 2 min