
Index Pages Security & Risk Analysis
wordpress.org/plugins/index-pagesAssign pages as the index page for WordPress custom post types, similar to the Posts Page.
Is Index Pages Safe to Use in 2026?
Generally Safe
Score 92/100Index Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "index-pages" plugin version 1.3.0.1 demonstrates a generally good security posture based on the static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the plugin's attack surface. Furthermore, the taint analysis found no unsanitized paths, indicating a lack of common vulnerabilities like cross-site scripting or path traversal that could arise from user-supplied input being improperly handled.
However, there are some areas for improvement. The analysis shows one SQL query that does not use prepared statements, presenting a potential risk for SQL injection if the query's input is not rigorously sanitized elsewhere. While output escaping is generally well-implemented (75% properly escaped), the remaining 25% could still pose a risk for cross-site scripting if unescaped data is rendered directly in the browser. The absence of nonce checks on entry points is also a concern, as it leaves potential vulnerabilities open to cross-site request forgery attacks.
The plugin's vulnerability history is entirely clean, with no known CVEs recorded. This is a strong positive indicator of past security diligence. Overall, "index-pages" v1.3.0.1 appears to be a secure plugin due to its minimal attack surface and lack of critical vulnerabilities. The primary areas of concern are the unparameterized SQL query and the potential for XSS through less-than-perfect output escaping, along with the lack of nonce checks.
Key Concerns
- SQL query without prepared statements
- Potential unescaped output exists
- Missing nonce checks
Index Pages Security Vulnerabilities
Index Pages Code Analysis
SQL Query Safety
Output Escaping
Index Pages Attack Surface
Maintenance & Trust
Index Pages Maintenance & Trust
Maintenance Signals
Community Trust
Index Pages Alternatives
Custom Post Type UI
custom-post-type-ui
Admin UI for creating custom content types like post types and taxonomies
Meta Box
meta-box
Meta Box plugin is a powerful, professional developer toolkit to create custom meta boxes and custom fields for your custom post types in WordPress.
Intuitive Custom Post Order
intuitive-custom-post-order
Intuitively reorder Posts, Pages, Custom Post Types, Taxonomies, and Sites with a simple drag-and-drop interface.
Custom Post Type Permalinks
custom-post-type-permalinks
Edit the permalink of custom post type.
Pods – Custom Content Types and Fields
pods
Pods is a framework for creating, managing, and deploying customized content types and fields for any project.
Index Pages Developer Profile
7 plugins · 1K total installs
How We Detect Index Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/index-pages/assets/css/index-pages.css/wp-content/plugins/index-pages/assets/js/index-pages.js/wp-content/plugins/index-pages/assets/js/index-pages.jsindex-pages/assets/css/index-pages.css?ver=index-pages/assets/js/index-pages.js?ver=