
Code Widget Security & Risk Analysis
wordpress.org/plugins/code-widgetCode widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
Is Code Widget Safe to Use in 2026?
Generally Safe
Score 85/100Code Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The code-widget plugin v1.0.15 demonstrates a strong security posture with several good practices evident. It boasts a limited attack surface with only one AJAX handler, and importantly, this handler appears to be protected by authentication checks. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests further contributes to its security. The high percentage of properly escaped output and the presence of nonce and capability checks are also positive indicators. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a commitment to secure coding or perhaps a lack of widespread security scrutiny. However, the analysis did not include taint analysis flows, which could reveal subtle vulnerabilities. While the current static analysis reveals no immediate critical risks, the lack of taint analysis means potential issues related to data sanitization and context could be present.
Key Concerns
- 88% of output escaped, 12% unescaped
- External HTTP request not detailed
- Taint analysis flows not analyzed
Code Widget Security Vulnerabilities
Code Widget Code Analysis
Output Escaping
Code Widget Attack Surface
AJAX Handlers 1
WordPress Hooks 5
Maintenance & Trust
Code Widget Maintenance & Trust
Maintenance Signals
Community Trust
Code Widget Alternatives
Safe PHP Code Widget
safe-php-code-widget
Adds a secure and simple widget in which you can use PHP and JavaScript code. Also you can use unfiltered HTML or just Text. Admin Use Only.
HTML Widget
html-widget
Adds a simple HTML widget with syntax highlighting for HTML, CSS and JS.
2MB Autocode
2mb-autocode
This plugin allows you to place predetermined text/html/php at the top or bottom of posts.
3D WP Tag Cloud-S
my-wp-tagcanvas
3D WP Tag Cloud-S draws and animates an HTML5 canvas based tag cloud.
Plugin Name: Disable Media
shortcode-for-sidebar
This Plugin Will enable short code in WordPress sidebar Widget. By default, wordpress doesn't support Short Code in Sidebar Widget.
Code Widget Developer Profile
5 plugins · 5K total installs
How We Detect Code Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/code-widget/lib/solbox-plugin-deactivation-survey/css/feedback-modal.css/wp-content/plugins/code-widget/lib/solbox-plugin-deactivation-survey/js/feedback-modal.jscode-widget-style?ver=code-widget-admin-script?ver=HTML / DOM Fingerprints
code-widgetdata-codewidget-fieldcodewidget_params/wp-json/codewidget/v1/settings