
ID Arrays Security & Risk Analysis
wordpress.org/plugins/id-arraysGet list of post IDs by taxonomy, post-type, template. Add ID column in posts, media, taxonomies, users screens with option to copy selected IDs.
Is ID Arrays Safe to Use in 2026?
Mostly Safe
Score 78/100ID Arrays is generally safe to use. 1 past CVE were resolved. Keep it updated.
The static analysis of the 'id-arrays' plugin v2.1.2 reveals a generally positive security posture regarding its direct attack surface and code signals. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, and crucially, no entry points are found to be unprotected. The plugin also demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and performing file operations or external HTTP requests. However, a concerning aspect is the output escaping, where only 75% of outputs are properly escaped, leaving a potential for vulnerabilities in the remaining 25% of outputs. The plugin's vulnerability history is a significant concern, with one unpatched medium severity CVE for Cross-Site Scripting (XSS). The fact that the last vulnerability was dated in the future (2026-01-29) is highly unusual and likely an error in the provided data, but the presence of an unpatched CVE is a clear risk. The absence of nonce and capability checks across the board is also a weakness, especially if any entry points were to be discovered or introduced in future versions, as it leaves the plugin vulnerable to CSRF and unauthorized actions.
In conclusion, while the plugin exhibits strengths in minimizing its attack surface and employing secure database practices, the partially unescaped output and the significant unpatched vulnerability history point to significant security risks. The lack of authentication checks in key areas further exacerbates these risks. The plugin would benefit greatly from addressing the unescaped outputs and patching the known CVE, along with implementing robust authentication mechanisms if any new entry points are ever introduced.
Key Concerns
- Unpatched CVE (Medium)
- Partially unescaped output
- No nonce checks
- No capability checks
ID Arrays Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ID Arrays <= 2.1.2 - Reflected Cross-Site Scripting
ID Arrays Code Analysis
Output Escaping
ID Arrays Attack Surface
WordPress Hooks 16
Maintenance & Trust
ID Arrays Maintenance & Trust
Maintenance Signals
Community Trust
ID Arrays Alternatives
Show Current Template – CTI
current-template-info
CTI is a WordPress plugin which show current template name file and post information(post id, post type, post taxonomy).
Copy Post and Page ID
copy-post-page-id
Easily view and copy Post ID and Page ID directly from the WordPress admin dashboard with a single click.
Quick ID Viewer
quick-id-viewer
Quickly view and copy post, page, custom post type, and taxonomy term IDs directly from the WordPress admin list view with a single click.
Ultimate Category Excluder
ultimate-category-excluder
Ultimate Category Excluder allows you to quickly and easily exclude categories from your front page, archives, feeds, and search results.
Advanced Sidebar Menu
advanced-sidebar-menu
Fully automatic sidebar menus.
ID Arrays Developer Profile
3 plugins · 220 total installs
How We Detect ID Arrays
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/id-arrays/id-arrays.css/wp-content/plugins/id-arrays/id-arrays.js/wp-content/plugins/id-arrays/id-arrays.jsid-arrays.css?ver=id-arrays.js?ver=HTML / DOM Fingerprints
ida_79_coldata-ida79-idida79_copy_selected_idsida79_array_copy