
CW Show on Selected Pages Security & Risk Analysis
wordpress.org/plugins/cw-show-on-selected-pages-sospHave you ever tried to display sidebar-content just on selected pages? You can realize this with this widget. You can choose wether you want to displa …
Is CW Show on Selected Pages Safe to Use in 2026?
Generally Safe
Score 85/100CW Show on Selected Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cw-show-on-selected-pages-sosp" plugin, in version 1.1, exhibits a strong security posture based on the provided static analysis. The complete absence of identifiable entry points such as AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the lack of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for all SQL queries are excellent security practices.
However, a notable concern arises from the low percentage of properly escaped output (27%). This suggests that user-supplied data or dynamic content might be rendered directly in the HTML without sufficient sanitization, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if attackers can influence the data being displayed. The absence of nonce and capability checks on any potential entry points (though none were identified) is also a missed opportunity for layered security, but less critical given the limited attack surface.
The plugin's vulnerability history is clean, with no recorded CVEs. This indicates a historically responsible development approach or simply a lack of significant past issues. While this is a positive sign, it does not negate the identified risks within the current code, particularly the output escaping deficiency. The overall assessment is that the plugin is currently well-defended against common web vulnerabilities due to its minimal attack surface and secure SQL practices, but the output escaping issue presents a tangible risk that should be addressed.
Key Concerns
- Low percentage of properly escaped output
CW Show on Selected Pages Security Vulnerabilities
CW Show on Selected Pages Code Analysis
Output Escaping
CW Show on Selected Pages Attack Surface
WordPress Hooks 1
Maintenance & Trust
CW Show on Selected Pages Maintenance & Trust
Maintenance Signals
Community Trust
CW Show on Selected Pages Alternatives
Custom & Recent Pages Widget
onodev-recent-pages-widget
A flexible widget to display selected or latest pages, with optional pagination. Compatible with both Classic and Block Widgets.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
CW Show on Selected Pages Developer Profile
2 plugins · 110 total installs
How We Detect CW Show on Selected Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cw-show-on-selected-pages-sosp/languagesHTML / DOM Fingerprints
cwsosp_widget_class