Display Categories Widget Security & Risk Analysis

wordpress.org/plugins/display-categories-widget

Display Categories Widget will display Child categories on your sidebar. Can be placed on widget in sidebar.

4K active installs v3.1 PHP + WP 5.0+ Updated Nov 3, 2019
categorieshide-categorieslist-categoriesselect-categorieswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Display Categories Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Display Categories Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The display-categories-widget plugin version 3.1 presents a generally positive security posture based on the provided static analysis. There are no identified entry points like AJAX handlers, REST API routes, or shortcodes that are exposed to users, and importantly, none of these are found to be unprotected. The code signals also indicate good practices, with no dangerous functions or file operations detected. All SQL queries are correctly utilizing prepared statements, and no external HTTP requests are made, reducing the risk of injection or remote code execution vulnerabilities. The absence of any recorded vulnerabilities in its history further bolsters confidence in its security. However, a significant concern arises from the output escaping analysis. With 80 total outputs and only 34% properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This weakness, despite the plugin's otherwise clean security profile, is a critical area that needs immediate attention.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Display Categories Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Display Categories Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
53
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

34% escaped80 total outputs
Attack Surface

Display Categories Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initdisplay_categories_widget.php:292
Maintenance & Trust

Display Categories Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedNov 3, 2019
PHP min version
Downloads85K

Community Trust

Rating96/100
Number of ratings25
Active installs4K
Developer Profile

Display Categories Widget Developer Profile

iteamweb

3 plugins · 4K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Display Categories Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
DisplayCategoriesWidget
Data Attributes
id="DisplayCategoriesWidget"class="DisplayCategoriesWidget"
FAQ

Frequently Asked Questions about Display Categories Widget