
Child pages Security & Risk Analysis
wordpress.org/plugins/childpagesDisplays the childpages of the page you're currently on
Is Child pages Safe to Use in 2026?
Generally Safe
Score 85/100Child pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "childpages" plugin version 1.1 presents a generally good security posture with no immediately apparent critical vulnerabilities. The plugin boasts a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, which significantly limits potential entry points for attackers. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. The SQL queries are all handled using prepared statements, which is a strong indicator of good practice against SQL injection. The taint analysis also shows no unsanitized paths, which is reassuring.
However, a significant concern arises from the output escaping. With 14 total outputs and 0% properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied or dynamically generated content displayed on the frontend without proper escaping is susceptible to malicious script injection. While there's no recorded vulnerability history, this doesn't guarantee future safety, especially given the identified XSS risk. The lack of nonce checks and capability checks, while not directly exploitable due to the limited attack surface, are generally considered good security practices for any WordPress plugin, and their absence here, coupled with the unescaped output, represents a weakness that could become exploitable if new entry points were introduced or existing ones inadvertently exposed.
Key Concerns
- All output is unescaped
- No capability checks
- No nonce checks
Child pages Security Vulnerabilities
Child pages Code Analysis
Output Escaping
Child pages Attack Surface
WordPress Hooks 6
Maintenance & Trust
Child pages Maintenance & Trust
Maintenance Signals
Community Trust
Child pages Alternatives
Child Pages Block
get-subpages-list
Gutenberg block gets child pages list of specific page
WP Subpages
wp-subpages
WP Subpages Widget is a simple plugin to allow for multiple instances to show child pages.
Widgets on Pages
widgets-on-pages
The easiest and highest rated way to Add Widgets or Sidebars to Posts and Pages using Visual editor, shortcodes or template tags.
CC Child Pages
cc-child-pages
Display WordPress child pages in a responsive grid or list using a shortcode, Gutenberg block or Elementor widget.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Child pages Developer Profile
3 plugins · 50 total installs
How We Detect Child pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/childpages/admin/css/wp-childpages-admin.css/wp-content/plugins/childpages/admin/js/wp-childpages-admin.js/wp-content/plugins/childpages/admin/js/wp-childpages-admin.jswp-childpages-admin.css?ver=wp-childpages-admin.js?ver=HTML / DOM Fingerprints
childpages-listchildpages-itemchildpages-titlechildpages-linkchildpages-excerptchildpages-thumbnailchildpages-datechildpages-author+1 moredata-childpages-parent-iddata-childpages-page-idwp_childpages_settings