
AR Subpages Widget Security & Risk Analysis
wordpress.org/plugins/ar-subpages-widgetLists subpages of the current parent page
Is AR Subpages Widget Safe to Use in 2026?
Generally Safe
Score 85/100AR Subpages Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "ar-subpages-widget" v2.0 demonstrates a generally strong security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the complete absence of dangerous functions, file operations, and external HTTP requests, along with the use of prepared statements for all SQL queries, are excellent security practices. However, a critical concern arises from the low percentage of properly escaped output (9%). This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered in the browser without proper sanitization, allowing attackers to inject malicious scripts. The lack of nonce checks and capability checks, while mitigated by the limited attack surface, also presents a potential weakness if new entry points are introduced without these crucial security measures. The plugin's vulnerability history is clean, with no recorded CVEs, which is positive. However, this should not be seen as a guarantee of future security, especially given the identified output escaping issues. In conclusion, while the plugin has a solid foundation with minimal attack vectors and secure data handling for SQL, the insufficient output escaping is a significant flaw that requires immediate attention to prevent XSS attacks. The absence of common vulnerability types in its history is encouraging, but the static analysis highlights a clear and actionable area for improvement.
Key Concerns
- Low output escaping percentage (9%)
- No nonce checks
- No capability checks
AR Subpages Widget Security Vulnerabilities
AR Subpages Widget Code Analysis
Output Escaping
AR Subpages Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
AR Subpages Widget Maintenance & Trust
Maintenance Signals
Community Trust
AR Subpages Widget Alternatives
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Happy Addons for Elementor
happy-elementor-addons
HappyAddons for Elementor-Get Header Footer, Single Post, Archive Page, Megamenu, Slider Builder & 143 Elementor Widgets.
Sticky Menu & Sticky Header
sticky-menu-or-anything-on-scroll
Sticky Menu or Sticky Header sticks elements at the top of the screen when you scroll, or create a floating sticky menu or fixed widget.
HT Mega Addons for Elementor – Elementor Widgets & Template Builder
ht-mega-for-elementor
Elementor addon offering 135+ widgets — Mega Menu, Ready Templates, Page Builder, Slider, Gallery, Post Grid, AI Writer & more.
AR Subpages Widget Developer Profile
1 plugin · 30 total installs
How We Detect AR Subpages Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ar_subpages_listwidget_subpages_current_pagefirst-menu-itemdata-widget_iddata-widget_namear_subpages_is_first