Category Checklist Expander Security & Risk Analysis

wordpress.org/plugins/category-checklist-expander

Increases the height of the category checklist meta box on the post editing screen so that all categories are shown.

100 active installs v1.0.1 PHP + WP 2.7+ Updated Dec 26, 2012
admincategoriesui
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Category Checklist Expander Safe to Use in 2026?

Generally Safe

Score 85/100

Category Checklist Expander has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The plugin "category-checklist-expander" v1.0.1 exhibits a mixed security posture. On the positive side, the static analysis reveals a remarkably small attack surface with zero identified entry points. Furthermore, there are no reported vulnerabilities in its history, suggesting a history of relatively secure development. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are all commendable practices.

However, significant concerns arise from the complete lack of output escaping. This means that any data rendered by the plugin could potentially be manipulated and injected into the page, leading to cross-site scripting (XSS) vulnerabilities, even if the current code doesn't immediately demonstrate such a flaw. The absence of nonce and capability checks across all potential (though currently nonexistent) entry points also indicates a potential for future security gaps if the plugin's functionality were to expand. The lack of taint analysis flows is noted, but this is likely due to the minimal attack surface rather than a deliberate security measure. Overall, while the plugin currently presents a low risk due to its limited scope and lack of historical vulnerabilities, the complete absence of output escaping is a critical oversight that warrants immediate attention.

Key Concerns

  • 0% output escaping
  • 0 Nonce checks
  • 0 Capability checks
Vulnerabilities
None known

Category Checklist Expander Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Category Checklist Expander Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Category Checklist Expander Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_headcategory-checklist-expander.php:41
Maintenance & Trust

Category Checklist Expander Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedDec 26, 2012
PHP min version
Downloads7K

Community Trust

Rating94/100
Number of ratings3
Active installs100
Developer Profile

Category Checklist Expander Developer Profile

Mark Jaquith

29 plugins · 176K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
3337 days
View full developer profile
Detection Fingerprints

How We Detect Category Checklist Expander

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
ui-tabs-paneltabs-panel
FAQ

Frequently Asked Questions about Category Checklist Expander