• Nathan Ingram’s old post (“What does this do?”) raises an important security concern. Old, insecure plugin versions remain in web-accessible folders with only a “security by obscurity” hope that the random folder names can’t be guessed. This may be an unlikely attack vector, but it’s just not good to keep obsolete and insecure code around a long time.

    A “delete old versions” feature — globally and per plugin — would be helpful.

    Even better: allow Plugversions to be limited in scope to individual, admin-selected plugins rather than every plugin.

You must be logged in to reply to this review.