Append extensions on Pages Security & Risk Analysis

wordpress.org/plugins/append-extensions-on-pages

This plugin helps to appends .html or .asp or .htm etc on the wordpress pages when used with permalink.

900 active installs v1.1.2 PHP + WP 3.1+ Updated Sep 9, 2017
html-on-permalinkadd-aspx-on-pagesadd-html-on-pagesadd-php-on-pagesappend-html-on-pages
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is Append extensions on Pages Safe to Use in 2026?

Use With Caution

Score 63/100

Append extensions on Pages has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 8yr ago
Risk Assessment

The "append-extensions-on-pages" plugin v1.1.2 exhibits a mixed security posture. While the static analysis indicates a minimal attack surface with no identified dangerous functions, SQL injection vulnerabilities, or unhandled file operations, there are significant concerns. Notably, 100% of outputs are not properly escaped, presenting a strong risk of Cross-Site Scripting (XSS) vulnerabilities. This is further compounded by a known medium severity CVE related to XSS that remains unpatched, indicating a historical tendency towards this type of vulnerability and a lack of timely security patching.

The vulnerability history reveals a pattern of XSS issues, with a recent medium severity vulnerability from September 2025. This suggests that developers may not be adequately addressing input sanitization and output encoding, even when vulnerabilities are identified. The absence of nonce and capability checks across all entry points (though the entry points themselves are zero) means that if any were introduced or inadvertently created, they would be unprotected.

In conclusion, despite a seemingly small attack surface in this specific version, the lack of output escaping and the presence of an unpatched XSS vulnerability are critical weaknesses. The plugin's history points to ongoing issues with secure coding practices regarding user-generated content. Users should exercise extreme caution, and developers should prioritize addressing the unescaped output and the existing CVE.

Key Concerns

  • Unpatched CVE (Medium Severity)
  • 100% of outputs unescaped
Vulnerabilities
1

Append extensions on Pages Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-57940medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Append extensions on Pages <= 1.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Append extensions on Pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Append extensions on Pages Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitappend_extension_on_pages.php:13
actionadmin_menuappend_extension_on_pages.php:19
actionadmin_initappend_extension_on_pages.php:63
filteruser_trailingslashitappend_extension_on_pages.php:127
Maintenance & Trust

Append extensions on Pages Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 9, 2017
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings7
Active installs900
Alternatives

Append extensions on Pages Alternatives

No alternatives data available yet.

Developer Profile

Append extensions on Pages Developer Profile

Suresh Kumar Mukhiya

4 plugins · 1K total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Append extensions on Pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/append-extensions-on-pages/

HTML / DOM Fingerprints

CSS Classes
welcome-panelwelcome-panel-contentwelcome-panel-column-containerwelcome-panel-columnwelcome-panel-last
Data Attributes
id="aeop-submit-button"
FAQ

Frequently Asked Questions about Append extensions on Pages