
Compact View Mode Security & Risk Analysis
wordpress.org/plugins/compact-view-modeView your post list in a more precise and compact way.
Is Compact View Mode Safe to Use in 2026?
Generally Safe
Score 85/100Compact View Mode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'compact-view-mode' plugin version 0.4.2 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points indicates a minimal attack surface. Furthermore, the code signals are overwhelmingly positive, with all outputs being properly escaped, no dangerous functions, file operations, or external HTTP requests detected. The plugin also avoids bundled libraries, which can often be a source of vulnerabilities.
However, a significant concern arises from the presence of a single SQL query that does not utilize prepared statements. While there are no known CVEs or recorded vulnerability history for this plugin, this single instance of raw SQL poses a potential risk for SQL injection if the input feeding this query is not rigorously sanitized upstream. The lack of nonce and capability checks, while seemingly less critical due to the minimal attack surface, could become a point of exploitation if new entry points were introduced in future versions without proper security considerations.
In conclusion, the plugin has a generally good security foundation with excellent output sanitization and a limited attack surface. The primary weakness lies in the unescaped SQL query, which warrants attention. The clean vulnerability history is a positive indicator, but it does not negate the inherent risk associated with raw SQL. Vigilance in maintaining this low-risk profile is recommended.
Key Concerns
- Raw SQL query without prepared statements
Compact View Mode Security Vulnerabilities
Compact View Mode Release Timeline
Compact View Mode Code Analysis
SQL Query Safety
Output Escaping
Compact View Mode Attack Surface
WordPress Hooks 4
Maintenance & Trust
Compact View Mode Maintenance & Trust
Maintenance Signals
Community Trust
Compact View Mode Alternatives
WP Admin UI Customize
wp-admin-ui-customize
Customize the management screen UI.
LH Archived Post Status
lh-archived-post-status
Allows posts and pages to be archived so you can remove content from the main loop and feed without having to trash it.
HiFi (Head Injection, Foot Injection)
hifi
HiFi is a head and foot injection plugin. It allows you to inject code into the head and foot areas of your posts and pages on a per-page basis.
Sortable Word Count Reloaded
sortable-word-count-reloaded
Adds a sortable column to the posts and pages admin list with the word count of each page/post.
Post Category Filter (WP Admin)
admin-category-filter
Quickly search and filter categories and taxonomies inside the WordPress admin.
Compact View Mode Developer Profile
5 plugins · 2K total installs
How We Detect Compact View Mode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/compact-view-mode/js/jquery.regex.min.js/wp-content/plugins/compact-view-mode/js/cvm-compact.min.js/wp-content/plugins/compact-view-mode/js/cvm-compact.js/wp-content/plugins/compact-view-mode/css/cvm-compact.min.css/wp-content/plugins/compact-view-mode/css/cvm-compact.css/wp-content/plugins/compact-view-mode/js/jquery.regex.min.js/wp-content/plugins/compact-view-mode/js/cvm-compact.min.js/wp-content/plugins/compact-view-mode/js/cvm-compact.jscvm-jquery-regexcvm-compactHTML / DOM Fingerprints
id="compact-view-mode"name="mode"cvm-jquery-regexcvm-compact