LIQUID RWD Plus Security & Risk Analysis

wordpress.org/plugins/liquid-rwd-plus

Switch to desktop view on smartphones.

300 active installs v1.0.6 PHP + WP 4.1+ Updated Dec 17, 2024
displaymobileresponsiveswitch
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LIQUID RWD Plus Safe to Use in 2026?

Generally Safe

Score 92/100

LIQUID RWD Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "liquid-rwd-plus" v1.0.6 exhibits a generally good security posture with no known CVEs or vulnerabilities recorded. The static analysis reveals a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, indicating strong initial security design. Furthermore, all SQL queries utilize prepared statements, and there are no detected file operations or external HTTP requests that could be exploited directly. The absence of critical or high-severity taint flows is also a positive indicator.

However, there are significant concerns arising from the output escaping. 100% of the identified outputs are not properly escaped. This represents a critical weakness, as unescaped output can lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization. The lack of nonce checks and capability checks on any entry points (though the attack surface is currently zero) also means that if new entry points are added in the future without these security measures, the plugin would be vulnerable. The presence of an external HTTP request, while not inherently a vulnerability, warrants careful review of its destination and data handling to ensure it doesn't introduce risks.

Overall, while the plugin avoids common pitfalls like unpatched vulnerabilities and direct SQL injection, the complete lack of output escaping is a severe oversight. This issue, if not addressed, could easily lead to the introduction of critical XSS vulnerabilities. The strengths lie in its clean attack surface and secure database interactions, but the weakness in output sanitization requires immediate attention.

Key Concerns

  • All outputs unescaped
  • 1 external HTTP request
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

LIQUID RWD Plus Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LIQUID RWD Plus Release Timeline

v1.0.6Current
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0
Code Analysis
Analyzed Mar 17, 2026

LIQUID RWD Plus Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

LIQUID RWD Plus Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_noticesliquid-rwd-plus.php:46
actionadmin_initliquid-rwd-plus.php:54
actionadmin_menuliquid-rwd-plus.php:70
actionwp_enqueue_scriptsliquid-rwd-plus.php:140
Maintenance & Trust

LIQUID RWD Plus Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 17, 2024
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs300
Developer Profile

LIQUID RWD Plus Developer Profile

lqd

9 plugins · 16K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
617 days
View full developer profile
Detection Fingerprints

How We Detect LIQUID RWD Plus

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/liquid-rwd-plus/js/jquery.cookie.js/wp-content/plugins/liquid-rwd-plus/js/rwd.js
Script Paths
/liquid-rwd-plus/js/jquery.cookie.js/liquid-rwd-plus/js/rwd.js
Version Parameters
liquid-rwd-plus/js/jquery.cookie.js?ver=liquid-rwd-plus/js/rwd.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrappostboxinside
HTML Comments
recommend settings
Data Attributes
liquid_rwd_plus_toggle
FAQ

Frequently Asked Questions about LIQUID RWD Plus