Create Pages on Multisite WordPress Security & Risk Analysis

wordpress.org/plugins/create-pages-on-multisite

Automate adding the same page on multiple installs of a WordPress multisite.

10 active installs v1.0.1 PHP + WP 3.8.8+ Updated Feb 27, 2024
add-pagescreate-pagesmulti-sitemultisite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Create Pages on Multisite WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Create Pages on Multisite WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "create-pages-on-multisite" plugin v1.0.1 exhibits a mixed security posture. While it avoids dangerous functions, raw SQL queries, and file operations, significant concerns arise from the lack of input sanitization and authorization checks. The presence of an unprotected AJAX handler represents a direct attack vector. The fact that 100% of its outputs are unescaped is a critical flaw, opening the door to Cross-Site Scripting (XSS) vulnerabilities. The single identified taint flow with unsanitized paths, although not classified as critical or high severity, coupled with the lack of nonce and capability checks, points to potential vulnerabilities that could be exploited by an attacker. The plugin's clean vulnerability history is a positive sign, suggesting responsible development practices thus far. However, the identified code weaknesses, particularly the unprotected AJAX handler and unescaped output, present immediate risks that should be addressed.

Key Concerns

  • Unprotected AJAX handler
  • Unescaped output
  • Flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Create Pages on Multisite WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Create Pages on Multisite WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
3 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared3 total queries

Output Escaping

0% escaped5 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
<content> (inc\content.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Create Pages on Multisite WordPress Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_buildpageblogwpriders-page-on-all.php:24
WordPress Hooks 2
actionadmin_enqueue_scriptsinc\content.php:3
actionadmin_menuwpriders-page-on-all.php:23
Maintenance & Trust

Create Pages on Multisite WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested3.8.41
Last updatedFeb 27, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Create Pages on Multisite WordPress Developer Profile

wpriders

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Create Pages on Multisite WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
data-target="#wpriders-create-page-modal"
JS Globals
wpriders_page_on_all_ajax_object
REST Endpoints
/wp-json/wpriders-cpb/v1/create-page
FAQ

Frequently Asked Questions about Create Pages on Multisite WordPress