
CMS Tree Page View Security & Risk Analysis
wordpress.org/plugins/cms-tree-page-viewAdds a tree view of all pages & custom posts. Get a great overview + options to drag & drop to reorder & option to add multiple pages.
Is CMS Tree Page View Safe to Use in 2026?
Generally Safe
Score 91/100CMS Tree Page View has a strong security track record. Known vulnerabilities have been patched promptly.
The "cms-tree-page-view" v1.6.8 plugin presents a mixed security posture. On the positive side, the plugin exclusively uses prepared statements for its SQL queries, which is a strong defense against SQL injection. It also correctly implements nonce checks and capability checks for most of its entry points, and avoids file operations and external HTTP requests. However, significant concerns arise from its attack surface. All four identified AJAX handlers lack authorization checks, making them directly exploitable if a vulnerability exists within their logic. This is further compounded by the taint analysis revealing two flows with unsanitized paths, indicating a potential for input manipulation that could lead to unintended consequences.
Key Concerns
- AJAX handlers without auth checks
- Taint flows with unsanitized paths
- Low output escaping percentage
- Medium severity vulnerability history (3 total)
CMS Tree Page View Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
CMS Tree Page View <= 1.6.7 - Reflected Cross-Site Scripting via 'post_type'
CMS Tree Page View < 1.4 - Missing Authorization Checks
CMS Tree Page View < 0.8.9 - Cross-Site Scripting
CMS Tree Page View Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
CMS Tree Page View Attack Surface
AJAX Handlers 4
WordPress Hooks 11
Maintenance & Trust
CMS Tree Page View Maintenance & Trust
Maintenance Signals
Community Trust
CMS Tree Page View Alternatives
Auto Attachments Cleaner
auto-attachments-cleaner
Automatically deletes attachments on post delete
Custom HTML/PHP Post Templates
html-php-pages-and-posts
Use your HTML or PHP files for any page or post.
Simple Custom Posts per Page
simple-custom-posts-per-page
This plugin allows to configure the number of posts displayed for every custom post registered.
Landing Page Creator With Custom Posts
landing-page-creator-with-custom-posts
Create landing pages, A-B tests, or other types of pages using custom posts. Set background color, background image or video, amount of content column …
Duplicate Page
duplicate-page
Duplicate Posts, Pages and Custom Posts easily using single click
CMS Tree Page View Developer Profile
11 plugins · 361K total installs
How We Detect CMS Tree Page View
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cms-tree-page-view/css/cms-tree-page-view.css/wp-content/plugins/cms-tree-page-view/css/jquery-ui.css/wp-content/plugins/cms-tree-page-view/css/style.css/wp-content/plugins/cms-tree-page-view/js/cms-tree-page-view.js/wp-content/plugins/cms-tree-page-view/js/jquery-ui.js/wp-content/plugins/cms-tree-page-view/js/jquery-ui-sortable.js/wp-content/plugins/cms-tree-page-view/js/jquery.cookie.js/wp-content/plugins/cms-tree-page-view/js/jquery.jeditable.js+2 more/wp-content/plugins/cms-tree-page-view/js/cms-tree-page-view.js/wp-content/plugins/cms-tree-page-view/js/jquery-ui.js/wp-content/plugins/cms-tree-page-view/js/jquery-ui-sortable.js/wp-content/plugins/cms-tree-page-view/js/jquery.cookie.js/wp-content/plugins/cms-tree-page-view/js/jquery.jeditable.js/wp-content/plugins/cms-tree-page-view/js/jquery.livequery.js+1 morecms-tree-page-view/css/cms-tree-page-view.css?ver=cms-tree-page-view/css/jquery-ui.css?ver=cms-tree-page-view/css/style.css?ver=cms-tree-page-view/js/cms-tree-page-view.js?ver=cms-tree-page-view/js/jquery-ui.js?ver=cms-tree-page-view/js/jquery-ui-sortable.js?ver=cms-tree-page-view/js/jquery.cookie.js?ver=cms-tree-page-view/js/jquery.jeditable.js?ver=cms-tree-page-view/js/jquery.livequery.js?ver=cms-tree-page-view/js/jquery.url.js?ver=HTML / DOM Fingerprints
cms-tree-page-view-containercms-tpv-rowcms-tpv-page-titlecms-tpv-page-statuscms-tpv-page-ordercms-tpv-post-actionscms-tpv-page-parentcms-tpv-page-type+9 more<!-- cms-tree-page-view --><!-- End cms-tree-page-view --><!-- Added 2015-01-09 --><!-- sf_d($_POST) -->+3 moredata-post-iddata-ref-post-iddata-post-typedata-post-parentdata-post-statusdata-cms-tpv-noncecms_tpv_get_childscms_tpv_move_pagecms_tpv_add_pagecms_tpv_add_pagesCMS_TPV_URLCMS_TPV_VERSION+4 more