
Custom Wishlist Security & Risk Analysis
wordpress.org/plugins/custom-wishlistCreate wishlists with custom post types
Is Custom Wishlist Safe to Use in 2026?
Generally Safe
Score 85/100Custom Wishlist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-wishlist" plugin v1.0.0 exhibits a mixed security posture. While it has no recorded historical vulnerabilities or dangerous code signals, the static analysis reveals significant areas for concern. The plugin has a notable attack surface with one unprotected AJAX handler, indicating a potential entry point for unauthenticated attackers. Furthermore, the low percentage of properly escaped output (17%) suggests a high risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered without adequate sanitization.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Custom Wishlist Security Vulnerabilities
Custom Wishlist Code Analysis
SQL Query Safety
Output Escaping
Custom Wishlist Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 4
Maintenance & Trust
Custom Wishlist Maintenance & Trust
Maintenance Signals
Community Trust
Custom Wishlist Alternatives
WP Blog and Widgets
wp-blog-and-widgets
A quick, easy way to add a Blog custom post type, Blog widget to WordPress. Also, work with the Gutenberg shortcode block.
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
YITH WooCommerce Wishlist
yith-woocommerce-wishlist
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.6.x compatible.
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Custom Wishlist Developer Profile
4 plugins · 60 total installs
How We Detect Custom Wishlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-wishlist/assets/css/styles.css/wp-content/plugins/custom-wishlist/assets/js/main.jscustom-wishlist/assets/js/main.js?ver=custom-wishlist/assets/css/styles.css?ver=HTML / DOM Fingerprints
cwl-wishlistcwl_ajaxurlcwl_msg_okcwl_msg_ko<div class="cwl-wishlist"><h2>My wishlist<h2>My wishlist