Category Archive Widget Security & Risk Analysis

wordpress.org/plugins/category-archive-widget

The Category Archive widget displays a monthly or yearly archive of posts for one specific category.

800 active installs v1.2 PHP 7.4+ WP 6.0+ Updated Jun 14, 2023
archivecategory
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Category Archive Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Category Archive Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The category-archive-widget plugin version 1.2 exhibits a generally strong security posture based on the static analysis and vulnerability history provided. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points, coupled with zero identified dangerous functions, raw SQL queries, or external HTTP requests, suggests a limited attack surface and a proactive approach to preventing common web vulnerabilities. The fact that all SQL queries utilize prepared statements is a significant positive security control.

However, the analysis does highlight areas for improvement. The significantly low percentage of properly escaped output (20%) is a notable concern. Insufficient output escaping can lead to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into pages viewed by other users. The lack of any recorded vulnerabilities in its history is a positive indicator, suggesting the plugin has been developed with security in mind or has had security issues addressed promptly in the past. Despite the strengths, the potential for XSS due to poor output escaping remains the primary concern.

In conclusion, while the plugin has a robust foundation with a small attack surface and secure data handling practices (prepared statements), the prevalent issue of unescaped output presents a tangible risk. The absence of past vulnerabilities is encouraging, but it does not negate the need to address the identified output escaping deficiencies to ensure a more secure user experience.

Key Concerns

  • Low percentage of properly escaped output (20%)
Vulnerabilities
None known

Category Archive Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Category Archive Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped40 total outputs
Attack Surface

Category Archive Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initcategory-archive-widget.php:259
Maintenance & Trust

Category Archive Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJun 14, 2023
PHP min version7.4
Downloads6K

Community Trust

Rating100/100
Number of ratings5
Active installs800
Developer Profile

Category Archive Widget Developer Profile

Kaz Kadalashvili

3 plugins · 11K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Category Archive Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/category-archive-widget/widget.css/wp-content/plugins/category-archive-widget/widget.js
Script Paths
/wp-content/plugins/category-archive-widget/widget.js
Version Parameters
category-archive-widget/widget.css?ver=category-archive-widget/widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
category-archive-widget
FAQ

Frequently Asked Questions about Category Archive Widget