
Include Widget Security & Risk Analysis
wordpress.org/plugins/include-widgetIncludes a file's contents in the widget.
Is Include Widget Safe to Use in 2026?
Generally Safe
Score 85/100Include Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "include-widget" plugin version 0.4 exhibits a seemingly strong security posture based on the provided static analysis. It reports zero AJAX handlers, REST API routes, shortcodes, or cron events, indicating a very small attack surface. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for SQL queries are all positive security practices. The plugin also has no recorded vulnerabilities, CVEs, or critical taint flows, which suggests a history of secure development.
However, a significant concern arises from the "Output escaping" metric. With 10 total outputs and 0% properly escaped, this indicates a high probability of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that originates from user input or external sources without proper sanitization and escaping is susceptible to exploitation. The lack of nonce checks and capability checks, while not explicitly tied to an attack surface, further reduces the robustness of the plugin against potential privilege escalation or unauthorized actions, especially if any unforeseen entry points were to be discovered or introduced in future versions.
In conclusion, while the plugin's small attack surface and lack of known vulnerabilities are strengths, the complete absence of output escaping is a critical weakness that overshadows these positives. This makes the plugin highly vulnerable to XSS attacks. A balanced view would highlight the developer's apparent effort to avoid common pitfalls like raw SQL and dangerous functions, but this is severely undermined by the critical failure in output sanitization.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
Include Widget Security Vulnerabilities
Include Widget Release Timeline
Include Widget Code Analysis
Output Escaping
Include Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Include Widget Maintenance & Trust
Maintenance Signals
Community Trust
Include Widget Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Include Widget Developer Profile
2 plugins · 20 total installs
How We Detect Include Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/include-widget/js/include-widget.js/wp-content/plugins/include-widget/css/include-widget.css/wp-content/plugins/include-widget/js/include-widget.jsinclude-widget.css?ver=include-widget.js?ver=HTML / DOM Fingerprints
includeid="include-widget"