
Bulk Page Creator Security & Risk Analysis
wordpress.org/plugins/bulk-page-creatorAllows you to create multiple pages in a batch/bulk manner saving time when initially setting up your WordPress site
Is Bulk Page Creator Safe to Use in 2026?
Mostly Safe
Score 84/100Bulk Page Creator is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "bulk-page-creator" plugin v1.1.4 exhibits a mixed security posture. While the static analysis shows a seemingly small attack surface with no identified unprotected entry points like AJAX handlers, REST API routes, or shortcodes, and a low number of dangerous functions or file operations, there are significant concerns regarding its handling of data and past vulnerabilities.
The most notable weakness is the presence of a single SQL query that does not utilize prepared statements, increasing the risk of SQL injection. Furthermore, only 50% of output escaping is properly handled, leaving potential avenues for Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while showing no critical or high severity flows, is based on a limited number of flows analyzed, which may not cover all potential scenarios.
The plugin's vulnerability history reveals one high-severity CVE, specifically a Cross-Site Request Forgery (CSRF). The fact that this vulnerability is no longer unpatched is positive, but the historical presence of a high-severity issue, especially CSRF which can be a precursor or companion to other attacks, warrants caution. The absence of recent vulnerabilities could indicate improved development practices or simply a lack of recent focused auditing. Overall, while the plugin has a relatively small attack surface, the unescaped output and raw SQL query present immediate risks, and the past high-severity CSRF vulnerability suggests a need for continued vigilance.
Key Concerns
- SQL query not using prepared statements
- Output escaping not properly handled (50%)
- One high severity CVE historically
Bulk Page Creator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Bulk Page Creator <= 1.1.3 - Cross-Site Request Forgery to Arbitrary Page Creation
Bulk Page Creator Code Analysis
SQL Query Safety
Output Escaping
Bulk Page Creator Attack Surface
WordPress Hooks 3
Maintenance & Trust
Bulk Page Creator Maintenance & Trust
Maintenance Signals
Community Trust
Bulk Page Creator Alternatives
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
Waka Bulk Page
waka-bulk-page
Bulk page creation for setting up quickly your website. Intuitive and easy to use.
Create Pages on Multisite WordPress
create-pages-on-multisite
Automate adding the same page on multiple installs of a WordPress multisite.
Bulk Page Creator Developer Profile
3 plugins · 11K total installs
How We Detect Bulk Page Creator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bulk-page-creator/my-style.css/wp-content/plugins/bulk-page-creator/my-script.js/wp-content/plugins/bulk-page-creator/my-script.jsHTML / DOM Fingerprints
sc-bpc-divsc-pagesid="sc-bpc-div"id="sc-pages"id="multiPages"id="sc-page-name"id="page_ids"id="page_template"+7 more[pagetitle]