
Catch Web Tools Security & Risk Analysis
wordpress.org/plugins/catch-web-toolsA top-notch modular plugin that can greatly enhance the capabilities of a WordPress website with its powerful features.
Is Catch Web Tools Safe to Use in 2026?
Generally Safe
Score 100/100Catch Web Tools has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "catch-web-tools" v3.1 plugin exhibits a generally strong security posture, with significant strengths in its handling of entry points and output escaping. The static analysis indicates a well-defined attack surface with all identified AJAX handlers and REST API routes properly secured with authentication or permission checks. The absence of dangerous functions, file operations, and external HTTP requests is also a positive indicator. Furthermore, the plugin demonstrates robust use of nonce and capability checks, suggesting good security awareness in its development.
However, a critical concern arises from the SQL query handling. The analysis reveals one SQL query that is not using prepared statements, posing a significant risk of SQL injection vulnerabilities. While the plugin has a history of a medium-severity CVE related to Missing Authorization, it's noteworthy that this vulnerability is currently patched and not present in this version. The lack of taint analysis data limits the ability to uncover complex or multi-stage vulnerabilities, but the direct SQL query issue is a clear and actionable finding. Overall, the plugin is well-protected against common web vulnerabilities, but the unescaped SQL query presents a notable risk that needs immediate attention.
Key Concerns
- Raw SQL query without prepared statements
Catch Web Tools Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Catch Web Tools <= 2.7.0 - Missing Authorization
Catch Web Tools Release Timeline
Catch Web Tools Code Analysis
SQL Query Safety
Output Escaping
Catch Web Tools Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 76
Maintenance & Trust
Catch Web Tools Maintenance & Trust
Maintenance Signals
Community Trust
Catch Web Tools Alternatives
Catch IDs
catch-ids
What this plugin does is to shows the IDs on admin section.
Gmt Post IDs
gmt-post-ids
This plugin displays the IDs in the admin section.
All In One Login — WP Admin Login Page Security and Customization with Google reCAPTCHA, Social Login, Limit Login Attempt, 2FA, and more.
change-wp-admin-login
Do you want to secure and customize the WordPress login page? Download the All in One Login plugin for login page security and customization.
Reveal IDs
reveal-ids-for-wp-admin-25
What this plugin does is to reveal most removed IDs on admin pages, as it was in versions prior to 2.5.
Change WordPress Login Logo
change-login-logo
Upload your logo for WordPress login page instead of the usual WordPress logo with simple settings.
Catch Web Tools Developer Profile
156 plugins · 226K total installs
How We Detect Catch Web Tools
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/catch-web-tools/admin/css/admin-dashboard.css/wp-content/plugins/catch-web-tools/admin/css/admin.css/wp-content/plugins/catch-web-tools/admin/js/admin.js/wp-content/plugins/catch-web-tools/admin/js/catch-updater-admin.js/wp-content/plugins/catch-web-tools/admin/css/catch-updater-admin.css/wp-content/plugins/catch-web-tools/admin/js/catch-ids.js/wp-content/plugins/catch-web-tools/admin/css/catch-ids.css/wp-content/plugins/catch-web-tools/css/font-awesome/css/all.min.css/wp-content/plugins/catch-web-tools/admin/js/admin.js/wp-content/plugins/catch-web-tools/admin/js/jquery.matchHeight.min.js/wp-content/plugins/catch-web-tools/css/font-awesome/css/all.min.css/wp-content/plugins/catch-web-tools/admin/css/admin.css/wp-content/plugins/catch-web-tools/admin/css/admin-dashboard.css/wp-content/plugins/catch-web-tools/admin/js/catch-updater-admin.js+3 more/wp-content/plugins/catch-web-tools/admin/js/admin.js?ver=/wp-content/plugins/catch-web-tools/css/font-awesome/css/all.min.css?ver=/wp-content/plugins/catch-web-tools/admin/css/admin.css?ver=/wp-content/plugins/catch-web-tools/admin/css/admin-dashboard.css?ver=/wp-content/plugins/catch-web-tools/admin/js/catch-updater-admin.js?ver=/wp-content/plugins/catch-web-tools/admin/css/catch-updater-admin.css?ver=/wp-content/plugins/catch-web-tools/admin/js/catch-ids.js?ver=/wp-content/plugins/catch-web-tools/admin/css/catch-ids.css?ver=HTML / DOM Fingerprints
catchwebtools-plugin-optionsCATCHWEBTOOLS_URLCATCHWEBTOOLS_VERSIONCATCHWEBTOOLS_PATHCATCHWEBTOOLS_BASENAME