
Combined Image and Text Widget Security & Risk Analysis
wordpress.org/plugins/combined-image-and-text-widgetA widget plugin for text and image combinations, with multilingual support.
Is Combined Image and Text Widget Safe to Use in 2026?
Generally Safe
Score 85/100Combined Image and Text Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'combined-image-and-text-widget' plugin, version 1.1, exhibits a generally positive security posture based on the provided static analysis. The absence of identified attack surface entry points like AJAX handlers, REST API routes, shortcodes, and cron events, along with zero critical taint flows, indicates a well-contained plugin. The fact that all SQL queries utilize prepared statements is a significant strength, mitigating risks of SQL injection. Furthermore, the plugin has no recorded vulnerabilities (CVEs), suggesting a history of stable and secure development.
However, there are notable areas for improvement. A concerning signal is the low percentage of properly escaped outputs (35%). This suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied or dynamically generated content may not be adequately sanitized before being displayed to users. The lack of any identified nonce checks or capability checks, while not directly indicative of a vulnerability in this specific analysis (due to the limited attack surface), represents a potential weakness if future updates introduce new entry points without proper authorization mechanisms. The plugin's overall security is good, but the unescaped output is a critical concern that needs immediate attention.
Key Concerns
- Significant percentage of unescaped output
- No nonce checks implemented
- No capability checks implemented
Combined Image and Text Widget Security Vulnerabilities
Combined Image and Text Widget Code Analysis
Output Escaping
Combined Image and Text Widget Attack Surface
WordPress Hooks 5
Maintenance & Trust
Combined Image and Text Widget Maintenance & Trust
Maintenance Signals
Community Trust
Combined Image and Text Widget Alternatives
Dashboard quick links widget
dashboard-quick-link-widget
A lightweight plugin to allows admins to create a admin dashboard widget with frequently accessed links for quick access.
Insights
insights
Insights allows you to quickly access and insert information (links, images, videos, maps..) into your blog posts.
Default Image Link
default-image-link
Select default settings for image link when you upload or insert images. Select default image link to None, Attachment Page, Media File or Custom URL.
Admin Links Widget
admin-links-sidebar-widget
This plugin provides a widget which can contain links to pages in the administration panel in one of your sidebars. These links are only visible to t …
QuickLinks Manager by Press.Zone
quicklinks-manager
QuickLinks Manager by Press.Zone lets you create and manage custom quick links in the WordPress dashboard for easier navigation.
Combined Image and Text Widget Developer Profile
1 plugin · 90 total installs
How We Detect Combined Image and Text Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/combined-image-and-text-widget/citw.jsHTML / DOM Fingerprints
citw_image_containercitw_inner_widget_textname="citw_url_schema"name="citw_enable_img_alt"