
AH Display Widgets Security & Risk Analysis
wordpress.org/plugins/ah-display-widgetsSimply hide widgets on specified pages. Adds checkboxes to each widget to either show or hide it on every site page.
Is AH Display Widgets Safe to Use in 2026?
Generally Safe
Score 85/100AH Display Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ah-display-widgets" plugin, version 1.0.3, presents a concerning security posture due to a significant lack of authorization checks on its attack surface. While the static analysis shows a clean slate regarding dangerous functions, SQL injection vulnerabilities, and file operations, the presence of one AJAX handler without authentication is a critical oversight. This unprotected entry point could be exploited by unauthenticated users to trigger plugin functionality, potentially leading to unintended consequences or information disclosure depending on the AJAX handler's logic. The taint analysis further highlights a flow with an unsanitized path, which, combined with the unprotected AJAX handler, suggests a potential for vulnerabilities if user-supplied data is not properly handled within that specific flow. The plugin's vulnerability history is clean, which is a positive indicator of past development practices, but it does not negate the immediate risks identified in the current code. Overall, the plugin exhibits good practices in areas like SQL query preparation and output escaping, but the fundamental security flaw of an exposed AJAX endpoint requires immediate attention.
Key Concerns
- Unprotected AJAX handler found
- Flow with unsanitized path
- Missing capability checks
- Missing nonce checks on AJAX
AH Display Widgets Security Vulnerabilities
AH Display Widgets Code Analysis
Output Escaping
Data Flow Analysis
AH Display Widgets Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
AH Display Widgets Maintenance & Trust
Maintenance Signals
Community Trust
AH Display Widgets Alternatives
Widget Master
wp-widget-master
The Widget Master plugin lets visitors to choose what widgets/blocks he want or wont to see on your pages. Visitor can hide widgets per PHP session.
Organic Builder Widgets – Simple WordPress Page Builder
organic-customizer-widgets
A simple WordPress page builder, Organic Builder Widgets provides a collection of 12 custom widgets to be used in the Customizer as content sections.
Widget Manager Light
widget-manager-light
Widget Manager lets you control on which pages widgets appear via nice and easy interface. Show or hide widgets. Display relevant content on your page …
Product Widget Slider for WooCommerce
woo-widget-product-slideshow
Beautifully lightweight, mobile & tablet responsive Product Widget Slider for WooCommerce plugin that packs a powerful marketing punch
Hide Widgets (SP Display Widgets)
sp-display-widgets
This plugin hide widgets on specified pages. Adds checkboxes to each widget to either show or hide it on every site page.
AH Display Widgets Developer Profile
8 plugins · 10K total installs
How We Detect AH Display Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ah-display-widgets/display-widgets.js/wp-content/plugins/ah-display-widgets/display-widgets.css/wp-content/plugins/ah-display-widgets/display-widgets.jsah-display-widgets/display-widgets.js?ver=ah-display-widgets/display-widgets.css?ver=HTML / DOM Fingerprints
ah-dw-settings<!-- AH Display Widgets --><!-- END AH Display Widgets -->data-dw-widget-iddata-dw-widget-instanceah_dw_vars