
ARCW Popover Addon Security & Risk Analysis
wordpress.org/plugins/arcw-popover-addonPopover Addon for Archives Calendar Widget
Is ARCW Popover Addon Safe to Use in 2026?
Generally Safe
Score 85/100ARCW Popover Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "arcw-popover-addon" v0.1.4 exhibits several concerning security practices, despite a lack of known historical vulnerabilities. The static analysis reveals a significant attack surface with two AJAX handlers, both of which lack authentication checks. This is a critical oversight, as it potentially allows any unauthenticated user to trigger plugin functionality, which could be exploited if further vulnerabilities exist within those handlers. Furthermore, the analysis indicates that none of the total outputs are properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin uses prepared statements for its SQL queries, mitigating the risk of SQL Injection, and has no recorded vulnerabilities in its history, these strengths are overshadowed by the immediate and severe risks identified in the code analysis.
Key Concerns
- Unprotected AJAX handlers
- Unescaped output detected
- No capability checks on entry points
ARCW Popover Addon Security Vulnerabilities
ARCW Popover Addon Code Analysis
Output Escaping
ARCW Popover Addon Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
ARCW Popover Addon Maintenance & Trust
Maintenance Signals
Community Trust
ARCW Popover Addon Alternatives
Collapsing Archives
collapsing-archives
This plugin uses Javascript to dynamically expand or collapse the set of months for each year and posts for each month in the archive listing of your …
Expanding Archives
expanding-archives
This plugin adds a new widget where you can view your old posts by expanding certain years and months.
Kalendář / Calendar
kalendar-cz
CZ
CPT Calender Widget for WordPress
cpt-calender-widget
Create Custom Post and and select CPT from dropdown.
Kalendarium CZ
kalendarium-cz
Shows actual date and the czech name days in the sidebar
ARCW Popover Addon Developer Profile
1 plugin · 30 total installs
How We Detect ARCW Popover Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/arcw-popover-addon/js/arcw-popover.min.js/wp-content/plugins/arcw-popover-addon/css/arcw-popover.css/wp-content/plugins/arcw-popover-addon/js/arcw-popover.min.jsarcw-popover-addon/js/arcw-popover.min.js?ver=arcw-popover-addon/css/arcw-popover.css?ver=HTML / DOM Fingerprints
ajaxurl/wp-json/arcw-popover-addon/v1/get-archives-list