
Lanyrd Splat Widget Security & Risk Analysis
wordpress.org/plugins/lanyrd-splat-widgetSimple configurable Lanyrd Badge (Content Splat) Widget.
Is Lanyrd Splat Widget Safe to Use in 2026?
Generally Safe
Score 85/100Lanyrd Splat Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lanyrd-splat-widget plugin v0.0.2 exhibits a mixed security posture. On one hand, the complete absence of known vulnerabilities and CVEs, coupled with the exclusive use of prepared statements for SQL queries, suggests a history of stable and potentially secure development. The plugin also demonstrates no external HTTP requests or file operations, which are common vectors for attacks.
However, the static analysis reveals significant concerns. The presence of the `create_function` dangerous function is a major red flag, as it can be used to execute arbitrary PHP code and is deprecated. Furthermore, a concerningly low output escaping rate (32%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, especially given the lack of capability checks and nonce checks, meaning any entry point, if discovered, could be exploited to inject malicious scripts.
While the current attack surface appears limited and the vulnerability history is clean, the identified code signals point to underlying weaknesses. The reliance on `create_function` and the poor output escaping practices present substantial risks that could be exploited if an attacker finds a way to interact with the plugin's code. Therefore, despite the clean history, the plugin requires immediate attention to address these critical coding flaws.
Key Concerns
- Presence of dangerous function 'create_function'
- Low output escaping rate (32%)
- No nonce checks
- No capability checks
Lanyrd Splat Widget Security Vulnerabilities
Lanyrd Splat Widget Code Analysis
Dangerous Functions Found
Output Escaping
Lanyrd Splat Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Lanyrd Splat Widget Maintenance & Trust
Maintenance Signals
Community Trust
Lanyrd Splat Widget Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Lanyrd Splat Widget Developer Profile
9 plugins · 21K total installs
How We Detect Lanyrd Splat Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lanyrd-splat-widget/lanyrd_splat.phpHTML / DOM Fingerprints
lanyrd-target-splatlanyrd-splatlanyrd-number-lanyrd-type-lanyrd-context-futurelanyrd-template-data-lanyrd-userdata-lanyrd-num-eventsdata-lanyrd-typedata-lanyrd-templateLanyrdBadge