
Dropdown multisite selector Security & Risk Analysis
wordpress.org/plugins/dropdown-multisite-selectorGives you the resources to make select field with redirecting options to a given URLs.
Is Dropdown multisite selector Safe to Use in 2026?
Generally Safe
Score 91/100Dropdown multisite selector has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "dropdown-multisite-selector" plugin v0.9.4 exhibits a mixed security posture. On the positive side, the static analysis reveals good practices such as the absence of dangerous functions, all SQL queries using prepared statements, and a single nonce and capability check, indicating an attempt to secure entry points. There are no identified flows with unsanitized paths in the taint analysis, and the code does not perform file operations or external HTTP requests, minimizing certain attack vectors.
However, there are significant concerns. A substantial portion of output (68%) is not properly escaped, presenting a considerable Cross-Site Scripting (XSS) risk. While the static analysis shows zero unprotected entry points, the vulnerability history reveals two past medium-severity CVEs, both related to XSS. The fact that these vulnerabilities existed, even if currently patched, suggests a recurring weakness in output sanitization, which is further evidenced by the high percentage of unescaped output in the current version. The presence of past vulnerabilities, particularly of the same type as indicated by the unescaped output, should be a strong indicator of potential future issues if not addressed.
In conclusion, while the plugin has made efforts to secure its core functionality with prepared statements and checks, the lack of robust output escaping remains a critical security weakness. The historical pattern of XSS vulnerabilities reinforces this concern. Users should be cautious, as the potential for XSS attacks is high due to the unescaped output, and the plugin's past indicates a susceptibility to this type of vulnerability.
Key Concerns
- High percentage of unescaped output
- History of medium severity XSS vulnerabilities
Dropdown multisite selector Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Dropdown Multisite selector < 0.9.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Dropdown Multisite selector <= 0.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
Dropdown multisite selector Release Timeline
Dropdown multisite selector Code Analysis
Output Escaping
Data Flow Analysis
Dropdown multisite selector Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
Dropdown multisite selector Maintenance & Trust
Maintenance Signals
Community Trust
Dropdown multisite selector Alternatives
Safe Redirect Manager
safe-redirect-manager
Safely manage your website's HTTP redirects.
Language Redirect
language-redirect
Redirects from the root site of a multisite project to a language specific network site.
jonimo Simple Redirect
jonimo-simple-redirect
Easily redirect users with specific roles to any url, page, tag or category a set number of times when they login or logout.
Primary Redirect
primary-redirect
Redirects users to a custom URL or their primary blog's dashboard after login, replacing the default WordPress behavior.
Redirect multisite user to their own site (UNMAINTAINED)
redirect-multisite-user-to-their-own-site
Redirect a multisite user to their own site.
Dropdown multisite selector Developer Profile
3 plugins · 1K total installs
How We Detect Dropdown multisite selector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dropdown-multisite-selector/assets/js/dms-admin.js/wp-content/plugins/dropdown-multisite-selector/assets/css/dms-admin.css/wp-content/plugins/dropdown-multisite-selector/assets/js/dms-front.js/wp-content/plugins/dropdown-multisite-selector/assets/css/dms-front.css/wp-content/plugins/dropdown-multisite-selector/assets/js/dms-admin.js/wp-content/plugins/dropdown-multisite-selector/assets/js/dms-front.jsdropdown-multisite-selector/assets/js/dms-admin.js?ver=0.7.0dropdown-multisite-selector/assets/js/dms-front.js?ver=dropdown-multisite-selector/assets/css/dms-front.css?ver=HTML / DOM Fingerprints
dms-containerdms-selectopen-in-new-tabdata-dms-tag-namedata-dms-valuedata-dms-siteurltrans_str<div class='dms-container'><label for='dms-select'><select class='dms-select'><option value=''>