
Append extensions on Pages Security & Risk Analysis
wordpress.org/plugins/append-extensions-on-pagesThis plugin helps to appends .html or .asp or .htm etc on the wordpress pages when used with permalink.
Is Append extensions on Pages Safe to Use in 2026?
Use With Caution
Score 63/100Append extensions on Pages has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "append-extensions-on-pages" plugin v1.1.2 exhibits a mixed security posture. While the static analysis indicates a minimal attack surface with no identified dangerous functions, SQL injection vulnerabilities, or unhandled file operations, there are significant concerns. Notably, 100% of outputs are not properly escaped, presenting a strong risk of Cross-Site Scripting (XSS) vulnerabilities. This is further compounded by a known medium severity CVE related to XSS that remains unpatched, indicating a historical tendency towards this type of vulnerability and a lack of timely security patching.
The vulnerability history reveals a pattern of XSS issues, with a recent medium severity vulnerability from September 2025. This suggests that developers may not be adequately addressing input sanitization and output encoding, even when vulnerabilities are identified. The absence of nonce and capability checks across all entry points (though the entry points themselves are zero) means that if any were introduced or inadvertently created, they would be unprotected.
In conclusion, despite a seemingly small attack surface in this specific version, the lack of output escaping and the presence of an unpatched XSS vulnerability are critical weaknesses. The plugin's history points to ongoing issues with secure coding practices regarding user-generated content. Users should exercise extreme caution, and developers should prioritize addressing the unescaped output and the existing CVE.
Key Concerns
- Unpatched CVE (Medium Severity)
- 100% of outputs unescaped
Append extensions on Pages Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Append extensions on Pages <= 1.1.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Append extensions on Pages Code Analysis
Output Escaping
Append extensions on Pages Attack Surface
WordPress Hooks 4
Maintenance & Trust
Append extensions on Pages Maintenance & Trust
Maintenance Signals
Community Trust
Append extensions on Pages Alternatives
No alternatives data available yet.
Append extensions on Pages Developer Profile
4 plugins · 1K total installs
How We Detect Append extensions on Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/append-extensions-on-pages/HTML / DOM Fingerprints
welcome-panelwelcome-panel-contentwelcome-panel-column-containerwelcome-panel-columnwelcome-panel-lastid="aeop-submit-button"