
Easy Hierarchy Security & Risk Analysis
wordpress.org/plugins/easy-hierarchyHierarchies made easy!
Is Easy Hierarchy Safe to Use in 2026?
Generally Safe
Score 100/100Easy Hierarchy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easy-hierarchy" plugin version 2.0.3 exhibits a very strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate a clean codebase with no dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilizing prepared statements. This demonstrates a commitment to secure coding practices in these critical areas.
However, the analysis does highlight a potential area for concern. While the total number of outputs is relatively small, a significant portion (36%) are not properly escaped. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before being outputted to the browser. The lack of any observed nonce or capability checks is also a notable omission, particularly in conjunction with the unescaped output, as it leaves the plugin vulnerable to CSRF attacks and unauthorized actions if any entry points were to be introduced in the future.
The vulnerability history is exceptionally clean, with no recorded CVEs of any severity. This suggests a history of secure development and maintenance, or a very low profile that hasn't attracted significant security research. Despite the positive historical data, the current static analysis findings, particularly the unescaped output and the absence of nonces/capability checks, warrant attention to ensure the plugin remains secure as it evolves.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
Easy Hierarchy Security Vulnerabilities
Easy Hierarchy Code Analysis
SQL Query Safety
Output Escaping
Easy Hierarchy Attack Surface
WordPress Hooks 6
Maintenance & Trust
Easy Hierarchy Maintenance & Trust
Maintenance Signals
Community Trust
Easy Hierarchy Alternatives
Admin Menu Tree Page View
admin-menu-tree-page-view
Get a tree view of all your pages directly in the admin menu. Search, add, edit, view, re-order – all is just one click away!
Nested Pages
wp-nested-pages
Nested Pages provides a drag and drop interface for managing pages & posts in the WordPress admin, while maintaining quick edit functionality.
Category Checklist Tree
category-checklist-tree
Preserves the category hierarchy on the post editing screen
Collapsible Categories in the Dashboard
collapsible-categories-in-the-dashboard
In the Dashboard, collapses sub categories into hidden submenus that can be expanded and collapsed. Keeps selected categories visible.
Which Template Am I
which-template-am-i
This plugin will display the name of the WordPress Template in use for the current page at in the footer. It only shows for logged in administrators.
Easy Hierarchy Developer Profile
13 plugins · 13K total installs
How We Detect Easy Hierarchy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-hierarchy/easy-hierarchy.phpHTML / DOM Fingerprints
eh-search-boxeh-hierarchy-overvieweh-page-treeeh-page-itemeh-page-item-inlineeh-page-titleeh-page-title-inlinetitle-count+5 moreid="eh-page-search"placeholder="Search pages..."jQuery