
Category and Subcategory List Widget Security & Risk Analysis
wordpress.org/plugins/category-subcategory-list-widgetThis widget allows to add/update icons for category or icon for custom taxonomy. It lists Categories in horizontal menu pattern.
Is Category and Subcategory List Widget Safe to Use in 2026?
Generally Safe
Score 100/100Category and Subcategory List Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "category-subcategory-list-widget" plugin v7.3 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and raw SQL queries are all positive indicators. The high percentage of properly escaped output and the presence of nonce checks further contribute to a secure foundation.
However, a significant concern is the complete lack of capability checks. While nonce checks are present, relying solely on them for AJAX handlers can leave the plugin vulnerable to privilege escalation if an attacker can trick a privileged user into triggering the AJAX action. The limited attack surface with only one unprotected AJAX handler is a positive, but the absence of capability checks on it is a notable oversight.
With zero recorded vulnerabilities and no history of CVEs, the plugin has a good track record. This suggests a commitment to security by the developers, or simply a lack of discovery in past versions. Overall, the plugin is well-coded with good sanitization practices, but the absence of capability checks on its entry point represents a distinct weakness that warrants attention.
Key Concerns
- Missing capability checks on AJAX handler
Category and Subcategory List Widget Security Vulnerabilities
Category and Subcategory List Widget Code Analysis
Output Escaping
Category and Subcategory List Widget Attack Surface
AJAX Handlers 1
WordPress Hooks 2
Maintenance & Trust
Category and Subcategory List Widget Maintenance & Trust
Maintenance Signals
Community Trust
Category and Subcategory List Widget Alternatives
Most Popular Categories
most-popular-categories
Display your most popular categories in a widget
Multiple Category Selection Widget
multiple-category-selection-widget
Filter posts by selecting multiple categories using dropdown menus. Available as a widget, block, or shortcode.
Flynsarmy Subcategory List Widget
subcategory-list-widget
Adds a widget that can displays subcategories of a given category (or top level).
GNA Cate List
gna-cate-list
[catelist] shortcodes with any post, page and widget.
OVN Category List Widget for Elementor
ovn-category-list-widget-for-elementor
Show Category List or Custom Taxonomy List
Category and Subcategory List Widget Developer Profile
2 plugins · 900 total installs
How We Detect Category and Subcategory List Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wn_statuswidget-core_special_widgets_categories-2-wn_showdata-widget_id