GP Display Child Categories Security & Risk Analysis

wordpress.org/plugins/gp-display-child-categories

GP Display Child Categories help you create a Widget custom to display on Sidebar or a area Widget.

10 active installs v1.0.0 PHP + WP 3.2+ Updated Feb 4, 2016
categorychild-categoriescustom-widgetwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GP Display Child Categories Safe to Use in 2026?

Generally Safe

Score 85/100

GP Display Child Categories has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "gp-display-child-categories" plugin v1.0.0 exhibits a generally strong security posture, primarily due to the absence of any identified vulnerabilities in its history and a lack of critical findings in the static analysis. The plugin demonstrates good practices by not employing dangerous functions, not performing file operations, and not making external HTTP requests. Furthermore, its SQL queries are 100% prepared, which is a significant positive indicator. The limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further contributes to its security.

However, there are some areas that warrant attention. The most notable concern is the low percentage of properly escaped output (10%). This suggests a potential risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered without adequate sanitization. Additionally, the complete absence of nonce checks and capability checks, while not inherently problematic given the current lack of entry points, could become a security weakness if the plugin's functionality expands in the future. The lack of any identified taint flows or vulnerabilities in its history is a positive sign, implying a well-maintained and secure codebase to date.

In conclusion, the plugin is currently in a secure state, with no known vulnerabilities and a well-controlled attack surface. The primary area for improvement lies in ensuring that all output is properly escaped to mitigate potential XSS risks. The developers should also consider implementing capability checks as a proactive security measure for future development.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

GP Display Child Categories Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GP Display Child Categories Release Timeline

vv.1.0
Code Analysis
Analyzed Mar 16, 2026

GP Display Child Categories Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

10% escaped10 total outputs
Attack Surface

GP Display Child Categories Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initgp-display-child-category-widget.php:13
Maintenance & Trust

GP Display Child Categories Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedFeb 4, 2016
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

GP Display Child Categories Developer Profile

giangmd93

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GP Display Child Categories

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about GP Display Child Categories