Limited Category Lists Widget Security & Risk Analysis

wordpress.org/plugins/limited-category-lists-widget

Limited Category Lists Widget is a wordPress widget, lists the limited category as shown in the name.

10 active installs v0.1 PHP + WP 2.0+ Updated May 7, 2008
categorylistlistssidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Limited Category Lists Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Limited Category Lists Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The "limited-category-lists-widget" plugin v0.1 exhibits a generally strong static security posture based on the provided data. It boasts zero AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no apparent entry points for external interaction. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is commendable. The plugin also exclusively uses prepared statements for SQL queries, which mitigates common SQL injection risks. However, a significant concern arises from the complete lack of output escaping. This means that any dynamic data rendered by the plugin is not being sanitized, leaving it vulnerable to Cross-Site Scripting (XSS) attacks where user-controlled data could be injected into the output. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator for this version. Despite the clean history, the unescaped output presents a critical security flaw that needs immediate attention, overshadowing the otherwise positive security signals.

Key Concerns

  • 0% properly escaped output
Vulnerabilities
None known

Limited Category Lists Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Limited Category Lists Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
20
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped20 total outputs
Attack Surface

Limited Category Lists Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionsave_postlimited-category-lists-widget.php:67
actionpost_deletedlimited-category-lists-widget.php:68
actionsidebar_admin_setuplimited-category-lists-widget.php:155
actionsidebar_admin_pagelimited-category-lists-widget.php:156
actionplugins_loadedlimited-category-lists-widget.php:164
Maintenance & Trust

Limited Category Lists Widget Maintenance & Trust

Maintenance Signals

WordPress version tested2.5.1
Last updatedMay 7, 2008
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Limited Category Lists Widget Developer Profile

tomoya

3 plugins · 20 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Limited Category Lists Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/limited-category-lists-widget/limited-category-lists-widget.php

HTML / DOM Fingerprints

Data Attributes
limited_catlists-title-limited_catlists-category-limited_catlists-limit-limited_catlists-submit-limited_catlists-numberlimited_catlists-number-submit
FAQ

Frequently Asked Questions about Limited Category Lists Widget