
Clean Archives Reloaded Security & Risk Analysis
wordpress.org/plugins/clean-archives-reloadedA slick, Javascript enhanced post archive list generator.
Is Clean Archives Reloaded Safe to Use in 2026?
Generally Safe
Score 85/100Clean Archives Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'clean-archives-reloaded' v3.2.0 exhibits a mixed security posture. On the positive side, the plugin has a very small attack surface with no apparent unprotected entry points, and there is no recorded vulnerability history. The absence of CVEs and common vulnerability types is encouraging.
However, the static analysis reveals significant concerns within the codebase itself. The presence of a dangerous `create_function` call is a red flag, as it can be a source of code injection vulnerabilities. Furthermore, the fact that 100% of SQL queries are not using prepared statements is a major risk, making the plugin highly susceptible to SQL injection attacks. The lack of output escaping for all identified outputs is another critical flaw, leaving the plugin vulnerable to Cross-Site Scripting (XSS) attacks. The absence of nonce and capability checks, while not directly tied to a specific entry point in this analysis, further weakens the overall security by not implementing fundamental WordPress security practices for potential future extensions or changes to the code.
While the plugin's lack of historical vulnerabilities and limited attack surface are strengths, the identified code-level weaknesses, particularly unescaped output and raw SQL queries, represent substantial risks. The presence of `create_function` adds to this concern. These issues require immediate attention to prevent potential exploitation.
Key Concerns
- 100% SQL queries not using prepared statements
- 0% properly escaped output
- Dangerous function call: create_function
- No nonce checks implemented
- No capability checks implemented
Clean Archives Reloaded Security Vulnerabilities
Clean Archives Reloaded Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Clean Archives Reloaded Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
Clean Archives Reloaded Maintenance & Trust
Maintenance Signals
Community Trust
Clean Archives Reloaded Alternatives
Advanced Posts/Page
advanced-posts-per-page
Fine grained control of how many of your posts appear on each of the various WordPress archive pages.
Expanding Archives
expanding-archives
This plugin adds a new widget where you can view your old posts by expanding certain years and months.
Custom Posts Per Page
custom-posts-per-page
Custom Posts Per Page provides a settings page in your WordPress admin that allows you to specify how many posts are displayed for different views.
Custom Posts Per Page Reloaded
custom-posts-per-page-reloaded
Custom Posts Per Page Reloaded provides a settings page in your WordPress admin that allows you to specify how many posts are displayed for different …
Posts per Cat
posts-per-cat
Group recent posts by category and show them inside boxes organized to columns.
Clean Archives Reloaded Developer Profile
213 plugins · 19.2M total installs
How We Detect Clean Archives Reloaded
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clean-archives-reloaded/car.css/wp-content/plugins/clean-archives-reloaded/car.js/wp-content/plugins/clean-archives-reloaded/car.jsclean-archives-reloaded/car.css?ver=clean-archives-reloaded/car.js?ver=HTML / DOM Fingerprints
car-collapsecar-yearmonthcar-monthlistingClean Archives Reloaded v3.2.0 | http://www.viper007bond.com/wordpress-plugins/clean-archives-reloaded/jQuery[cleanarchivesreloaded][cartotalposts]