
Add Any Extension to Pages Security & Risk Analysis
wordpress.org/plugins/add-any-extension-to-pagesAdd any extension of your choosing (e.g. .html, .htm, .jsp, .aspx, .cfm) to WordPress pages.
Is Add Any Extension to Pages Safe to Use in 2026?
Generally Safe
Score 99/100Add Any Extension to Pages has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the "add-any-extension-to-pages" plugin v1.5 reveals a generally good security posture concerning direct attack vectors. The absence of AJAX handlers, REST API routes, shortcodes, and cron events without authentication checks significantly reduces the immediate attack surface. Furthermore, the plugin demonstrates sound practices by exclusively using prepared statements for its SQL queries and having no file operations or external HTTP requests, which are common sources of vulnerabilities. The presence of nonce and capability checks, although limited, indicates an awareness of security principles.
However, concerns arise from the output escaping. With 60% of outputs properly escaped, there's a notable risk of Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs handle user-supplied data. The taint analysis shows no critical or high-severity flows with unsanitized paths, which is positive, but the limited number of flows analyzed might not capture all potential issues. The plugin's vulnerability history is a significant concern. Having two medium-severity CVEs in the past, particularly involving Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS), suggests recurring security weaknesses. The fact that the last vulnerability was in late 2023 indicates that these issues are relatively recent.
In conclusion, while the plugin has made strides in reducing its direct attack surface and adopting secure coding practices for database interactions, the partial output escaping and the history of XSS and CSRF vulnerabilities necessitate caution. The plugin's strengths lie in its minimal attack surface and secure database handling. Its weaknesses are primarily related to potential XSS vulnerabilities due to incomplete output escaping and the recurrence of past vulnerability types, highlighting a need for more robust input validation and output sanitization. Continuous monitoring and updates are crucial.
Key Concerns
- Unescaped output risks XSS
- History of medium severity CVEs (XSS/CSRF)
Add Any Extension to Pages Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Add Any Extension to Pages <= 1.4 - Cross-Site Request Forgery via aaetp_options_page
Add Any Extension to Pages <= 1.3 - Cross-Site Scripting
Add Any Extension to Pages Code Analysis
Output Escaping
Data Flow Analysis
Add Any Extension to Pages Attack Surface
WordPress Hooks 4
Maintenance & Trust
Add Any Extension to Pages Maintenance & Trust
Maintenance Signals
Community Trust
Add Any Extension to Pages Alternatives
Livemesh Addons by Elementor
addons-for-elementor
Elementor Addons that saves time with multiple ready-to-use drag and drop styles for 30+ essential widgets built for Elementor page builder.
WPBakery Page Builder Addons by Livemesh
addons-for-visual-composer
A collection of 25+ beautifully designed premium quality addons or extensions for WPBakery Page Builder.
Ultimate Addons for Beaver Builder – Lite
ultimate-addons-for-beaver-builder-lite
Extend Beaver Builder with powerful modules and ready-made templates to build stunning WordPress websites faster.
LA-Studio Element Kit for Elementor
lastudio-element-kit
The advanced addons for Elementor
aThemes Addons for Elementor
athemes-addons-for-elementor-lite
A collection of 30+ essential Elementor addons that let you create galleries, sliders, calls to action, forms, pricing tables, animations, and more.
Add Any Extension to Pages Developer Profile
7 plugins · 195K total installs
How We Detect Add Any Extension to Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-any-extension-to-pages/css/aaetp.cssHTML / DOM Fingerprints
side-labeltextboxaaetp-itemsaaetp_itemlistaaetp-sbaaetp-sboneaaetp-sbtwoaaetp-sbthree+2 moreid="aaetp_extension"name="aaetp_extension"id="aaetp-items"id="aaetp_itemlist"name="setup-update"id="aaetp-sb"+3 more