
Plugin Name: GMO Widget Custom Security & Risk Analysis
wordpress.org/plugins/gmo-widget-customThis is a useful widget customizer plugin which enables you to insert images, ad and recommendation banners.
Is Plugin Name: GMO Widget Custom Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Name: GMO Widget Custom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gmo-widget-custom" plugin version 1.2 exhibits a generally strong security posture with no known vulnerabilities or CVEs. The static analysis reveals a minimal attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. All SQL queries are properly prepared, and there are no file operations or external HTTP requests, which significantly reduces the risk of common web vulnerabilities. However, there are concerning signals within the code. The presence of the `create_function` dangerous function is a significant security risk as it can be exploited for arbitrary code execution if user input is not rigorously sanitized before being passed to it. Furthermore, the low percentage of properly escaped output (22%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where unescaped user-provided data could be injected into the page. The lack of nonce checks on any potential entry points (though none were found) and only one capability check, while not directly exploitable with the current attack surface, suggest a potential oversight in securing code that might be added in future versions.
Key Concerns
- Use of dangerous function 'create_function'
- Low percentage of properly escaped output
- No nonce checks found
Plugin Name: GMO Widget Custom Security Vulnerabilities
Plugin Name: GMO Widget Custom Code Analysis
Dangerous Functions Found
Output Escaping
Plugin Name: GMO Widget Custom Attack Surface
WordPress Hooks 4
Maintenance & Trust
Plugin Name: GMO Widget Custom Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Name: GMO Widget Custom Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Plugin Name: GMO Widget Custom Developer Profile
6 plugins · 250 total installs
How We Detect Plugin Name: GMO Widget Custom
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gmo-widget-custom/resources/js/image-widget.js/wp-content/plugins/gmo-widget-custom/resources/js/image-widget.jsgmo-widget-custom/resources/js/image-widget.js?ver=HTML / DOM Fingerprints
widget_customuploadertribe_previewdata-id="widget_custom"TribeImageWidget