
Extended Page List Security & Risk Analysis
wordpress.org/plugins/extended-page-listsAdd custom configured page lists to your posts, pages and sidebar.
Is Extended Page List Safe to Use in 2026?
Generally Safe
Score 85/100Extended Page List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'extended-page-lists' plugin v1.0 presents a mixed security posture. On the positive side, it boasts a very small attack surface with only one entry point (a shortcode) and no AJAX handlers or REST API routes. Crucially, there are no recorded vulnerabilities in its history, suggesting a potentially well-maintained or less targeted plugin. However, the static analysis reveals significant concerns regarding secure coding practices. The presence of the `create_function` is a major red flag due to its inherent security risks. Furthermore, the plugin uses SQL queries without prepared statements, which exposes it to SQL injection vulnerabilities. The low percentage of properly escaped output is also a significant weakness, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce and capability checks, while mitigated by the limited attack surface, leaves potential room for privilege escalation or unauthorized actions if the attack surface were to expand in future versions.
Key Concerns
- Dangerous function create_function used
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Extended Page List Security Vulnerabilities
Extended Page List Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Extended Page List Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Extended Page List Maintenance & Trust
Maintenance Signals
Community Trust
Extended Page List Alternatives
Easy Content Adder
easy-content-adder
A WordPress plugin to easily add custom content to all of your Pages, Posts, and Custom Post Types.
Embed Post
embed-post
Embed a Post within another Post or Page using [embed_post] shortcode.
WP Order By
wp-order-by
Simple and easy way to order your posts, pages or any other custom post-type in a various options.
Multiple Content Types
multiple-content-types
Easily select which content types (custom post types) you want to display on your main blog and archive pages.
End Content
end-content
Allows you to add content to the end of pages, posts or both.
Extended Page List Developer Profile
7 plugins · 170 total installs
How We Detect Extended Page List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extended-page-lists/css/epl.css/wp-content/plugins/extended-page-lists/js/epl.js/wp-content/plugins/extended-page-lists/js/epl.jsHTML / DOM Fingerprints
page-listpage-list-itempage-list-titlepage-list-contentpage-list-excerptdata-post-iddata-post-typedata-excerpt-lengthdata-excerpt-moredata-more-linkdata-show-thumbnail+3 moreepl_data<ul class="page-list"><li class="page-list-item"><span class="page-list-title"><span class="page-list-content">