
Chosen for WordPress Security & Risk Analysis
wordpress.org/plugins/chosenMake long, unwieldy select boxes much more user-friendly.
Is Chosen for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Chosen for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "chosen" v0.3 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and unescaped output are significant strengths. Furthermore, the plugin has no recorded vulnerabilities, including critical or high severity ones, and no history of known CVEs. This indicates a well-developed and diligently maintained codebase with respect to these common security pitfalls.
Despite the positive findings, there is one notable area for concern: the lack of nonce checks. While the attack surface is minimal (one shortcode) and there are no unprotected entry points identified, relying solely on capability checks (if any are implicitly present) for shortcode execution could potentially be exploited under specific circumstances, especially if the shortcode performs sensitive operations. The absence of taint analysis flows, while not indicating a problem, means that complex or indirect data manipulation vulnerabilities might not have been detected by this specific analysis method.
In conclusion, "chosen" v0.3 appears to be a secure plugin with excellent development practices in place. The primary weakness identified is the absence of nonce checks, which is a standard security measure for user-generated content or actions within WordPress. While the current risk is likely low due to the limited attack surface and lack of vulnerability history, implementing nonce checks would further strengthen its security and provide a more robust defense against potential cross-site request forgery (CSRF) attacks.
Key Concerns
- Missing nonce checks
Chosen for WordPress Security Vulnerabilities
Chosen for WordPress Code Analysis
Bundled Libraries
Chosen for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Chosen for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Chosen for WordPress Alternatives
WP Chosen
wp-chosen
Make long, unwieldy select boxes much more user-friendly.
WP Reset Filters
wp-reset-filters
WP Reset Filters adds a "Reset" button to filters
WP Datepicker
wp-datepicker
A great plugin to implement custom styled jQuery UI datepicker site-wide.
Contact Form7: Autocomplete
contact-form7-autocomplete
Enables adding a date field for Contact Form 7 Wordpress Plugin using jQuery UI\'s autocomplete Requires Contact form 7 4.2 or higher
Referrer Input for Contact Form 7
referrer-input-for-contact-form-7
Contact Form 7 Addon that creates a cache-resistant input that contains the URL of the page the user visited before the contact form page.
Chosen for WordPress Developer Profile
5 plugins · 440 total installs
How We Detect Chosen for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/chosen/chosen.css/wp-content/plugins/chosen/chosen.jquery.min.js/wp-content/plugins/chosen/wp-chosen.js/wp-content/plugins/chosen/chosen.jquery.min.js/wp-content/plugins/chosen/wp-chosen.jschosen/chosen.css?ver=chosen/chosen.jquery.min.js?ver=chosen/wp-chosen.js?ver=