
Create DB Tables Security & Risk Analysis
wordpress.org/plugins/create-db-tablesExtremely simple way for developers to create and manage new database tables in a quick and efective manner.
Is Create DB Tables Safe to Use in 2026?
Generally Safe
Score 85/100Create DB Tables has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'create-db-tables' v1.2.1 exhibits a concerning security posture primarily due to its complete lack of security checks and extensive use of raw SQL queries. While the static analysis shows zero known vulnerabilities historically and a small attack surface in terms of entry points, the code itself presents significant risks. The fact that 100% of the SQL queries are not prepared statements, combined with 4 taint flows identified as having unsanitized paths, indicates a high likelihood of SQL injection vulnerabilities. Furthermore, only 27% of output is properly escaped, raising concerns about cross-site scripting (XSS) risks. The absence of capability checks and nonce checks on any potential entry points, though there are currently none, leaves the plugin wide open to future exploitation if new entry points are introduced without proper security.
Despite the clean vulnerability history, this plugin is not secure. The internal code analysis reveals critical weaknesses that are likely to lead to vulnerabilities. The absence of any historical CVEs might suggest it's either a very new plugin, has not been actively targeted, or the analysis is incomplete. However, relying on this absence is a false sense of security. The plugin's strengths lie in its currently limited attack surface and lack of dangerous function usage. The weaknesses, however, are severe and stem from fundamental security oversights in how it handles data and database interactions, making it a high-risk plugin despite its clean history.
Key Concerns
- Raw SQL queries without prepared statements
- Taint flows with unsanitized paths
- Low output escaping percentage
- No capability checks
- No nonce checks
Create DB Tables Security Vulnerabilities
Create DB Tables Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Create DB Tables Attack Surface
WordPress Hooks 4
Maintenance & Trust
Create DB Tables Maintenance & Trust
Maintenance Signals
Community Trust
Create DB Tables Alternatives
DB Viewer
db-viewer
View your WordPress database directly inside your Dashboard. No need for phpMyAdmin or hosting panels.
Plugins Garbage Collector (Database Cleanup)
plugins-garbage-collector
Find unused database tables from deactivated or deleted plugins. You can delete unused database tables to reduce database volume and enhance site perf …
Change Table Prefix
change-table-prefix
Change the database table prefix first defined in your wp-config.php file.
Simple Table Manager
simple-table-manager
Enables viewing and editing table records and exporting them to CSV files through a minimal database interface from your dashboard.
DB-Views: Dashboards, Data Tables and Webforms
db-views-data-table
Add full database functionality to your website. Generative AI copilot turns your data into powerful database apps. Display advanced dashboards, data …
Create DB Tables Developer Profile
1 plugin · 20 total installs
How We Detect Create DB Tables
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/create-db-tables/css/add-new-table.css/wp-content/plugins/create-db-tables/css/create-db-tables.css/wp-content/plugins/create-db-tables/js/add-new-table.js/wp-content/plugins/create-db-tables/js/create-db-tables.js/wp-content/plugins/create-db-tables/js/add-new-table.js/wp-content/plugins/create-db-tables/js/create-db-tables.jscreate-db-tables/css/add-new-table.css?ver=create-db-tables/css/create-db-tables.css?ver=create-db-tables/js/add-new-table.js?ver=create-db-tables/js/create-db-tables.js?ver=HTML / DOM Fingerprints
db-tables-listdb-list-bodydb-list-headertable-rowtable-linksedit-coltable-links-editdelete-col+6 moreAlert: New Table CreatedAlert: Error Creating TableAlert: Duplicate id RowAlert: No Data Submitted+2 moredata-table-namecdbt_create_db_tables_create_menucdbt_add_new_table_pagecdbt_edit_existing_created_tablecdbt_view_table_datacdbt_plugin_main_settings_page_stylescdbt_add_page_styles