
Expanding Archives Security & Risk Analysis
wordpress.org/plugins/expanding-archivesThis plugin adds a new widget where you can view your old posts by expanding certain years and months.
Is Expanding Archives Safe to Use in 2026?
Generally Safe
Score 85/100Expanding Archives has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'expanding-archives' plugin v2.1.0 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, not performing file operations or external HTTP requests, and having no recorded vulnerability history. This suggests a generally careful development approach. However, a significant concern arises from its attack surface. The plugin exposes one REST API route without any permission callbacks. This means that any unauthenticated user could potentially interact with this endpoint, leading to unintended consequences if not handled securely. While taint analysis and dangerous function usage are clean, the lack of authorization on the REST API route is a critical oversight that could be exploited if that endpoint processes user-supplied input in a sensitive manner.
Key Concerns
- REST API route without permission callback
- Low percentage of properly escaped output
Expanding Archives Security Vulnerabilities
Expanding Archives Code Analysis
SQL Query Safety
Output Escaping
Expanding Archives Attack Surface
REST API Routes 1
WordPress Hooks 5
Maintenance & Trust
Expanding Archives Maintenance & Trust
Maintenance Signals
Community Trust
Expanding Archives Alternatives
Advanced Random Posts Widget
advanced-random-posts-widget
Provides flexible and advanced random posts. Display it via shortcode or widget with thumbnails, post excerpt, and much more!
Newpost Catch
newpost-catch
Thumbnails in new articles setting widget.
RaraTheme Companion
raratheme-companion
23 extremely useful custom widgets to create an engaging website.
Collapsing Categories
collapsing-categories
Adds a widget which uses Javascript to dynamically expand or collapse the set of posts for each category.
Recent Posts by Category Widget
recent-posts-by-category-widget
Just like the default Recent Posts widget except you can choose a category to pull posts from.
Expanding Archives Developer Profile
3 plugins · 3K total installs
How We Detect Expanding Archives
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/expanding-archives/assets/build/css/expanding-archives.css/wp-content/plugins/expanding-archives/assets/build/js/expanding-archives.jsexpanding-archives/assets/build/css/expanding-archives.css?ver=expanding-archives/assets/build/js/expanding-archives.js?ver=HTML / DOM Fingerprints
expanding-archivesexpanding-archives-widgetexpanding-archives-widget-yearexpanding-archives-widget-monthexpanding-archives-widget-month-postsdata-yeardata-monthdata-typeexpandingArchives/wp-json/expanding-archives/v1/posts