
Category Expander Security & Risk Analysis
wordpress.org/plugins/category-expanderAllows WordPress Admins to show only a selected few categories on the sidebar and hide the rest from view until visitor clicks "See All".
Is Category Expander Safe to Use in 2026?
Generally Safe
Score 85/100Category Expander has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The category-expander plugin version 0.9.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs, critical taint flows, and dangerous functions is a positive sign. Furthermore, the code does not appear to perform file operations or external HTTP requests, and it has no shortcodes or cron events, significantly limiting its attack surface. The adherence to prepared statements for SQL queries is also a strong security practice.
However, a significant concern arises from the complete lack of proper output escaping. With 15 total outputs and 0% properly escaped, this plugin is highly vulnerable to Cross-Site Scripting (XSS) attacks. Any data displayed to users without proper sanitization can be manipulated by attackers to inject malicious scripts. The absence of nonce checks and capability checks on any potential entry points (though none were identified in this analysis) is also a weakness that could be exploited if new entry points are introduced without proper security controls.
In conclusion, while the plugin avoids common severe vulnerabilities like SQL injection or known exploits, the critical flaw in output escaping presents a substantial risk. If the plugin handles user-supplied data or dynamic content that is then displayed, XSS vulnerabilities are highly likely. The plugin's vulnerability history showing no prior issues is encouraging but does not mitigate the identified XSS risk. Addressing the output escaping is paramount to improving its security.
Key Concerns
- 100% of outputs are not properly escaped
- No nonce checks found
- No capability checks found
Category Expander Security Vulnerabilities
Category Expander Code Analysis
Output Escaping
Category Expander Attack Surface
WordPress Hooks 5
Maintenance & Trust
Category Expander Maintenance & Trust
Maintenance Signals
Community Trust
Category Expander Alternatives
Collapsing Categories
collapsing-categories
Adds a widget which uses Javascript to dynamically expand or collapse the set of posts for each category.
Recent Posts by Category Widget
recent-posts-by-category-widget
Just like the default Recent Posts widget except you can choose a category to pull posts from.
Categorized Tag Cloud
categorized-tag-cloud
A cloud with the most used tags in a sidebar widget, filtered by post category.
GS Posts Widget
posts-widget
Best Responsive WordPress Posts Widget Plugin to display latest Posts elegantly.
SensitiveTagCloud
sensitive-tag-cloud
This wordpress plugin provides a tagcloud that shows tags depending of the current context (e.g. Category, Author, Tag, Post) only.
Category Expander Developer Profile
2 plugins · 20 total installs
How We Detect Category Expander
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-expander/category_expander.phpHTML / DOM Fingerprints
ce_hidden_licategory-listclrcategory-expanderid="ce_widget_ul"id="ce_seeall_li"jQuery