
LIQUID RWD Plus Security & Risk Analysis
wordpress.org/plugins/liquid-rwd-plusSwitch to desktop view on smartphones.
Is LIQUID RWD Plus Safe to Use in 2026?
Generally Safe
Score 92/100LIQUID RWD Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "liquid-rwd-plus" v1.0.6 exhibits a generally good security posture with no known CVEs or vulnerabilities recorded. The static analysis reveals a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events, indicating strong initial security design. Furthermore, all SQL queries utilize prepared statements, and there are no detected file operations or external HTTP requests that could be exploited directly. The absence of critical or high-severity taint flows is also a positive indicator.
However, there are significant concerns arising from the output escaping. 100% of the identified outputs are not properly escaped. This represents a critical weakness, as unescaped output can lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization. The lack of nonce checks and capability checks on any entry points (though the attack surface is currently zero) also means that if new entry points are added in the future without these security measures, the plugin would be vulnerable. The presence of an external HTTP request, while not inherently a vulnerability, warrants careful review of its destination and data handling to ensure it doesn't introduce risks.
Overall, while the plugin avoids common pitfalls like unpatched vulnerabilities and direct SQL injection, the complete lack of output escaping is a severe oversight. This issue, if not addressed, could easily lead to the introduction of critical XSS vulnerabilities. The strengths lie in its clean attack surface and secure database interactions, but the weakness in output sanitization requires immediate attention.
Key Concerns
- All outputs unescaped
- 1 external HTTP request
- No nonce checks
- No capability checks
LIQUID RWD Plus Security Vulnerabilities
LIQUID RWD Plus Release Timeline
LIQUID RWD Plus Code Analysis
Output Escaping
LIQUID RWD Plus Attack Surface
WordPress Hooks 4
Maintenance & Trust
LIQUID RWD Plus Maintenance & Trust
Maintenance Signals
Community Trust
LIQUID RWD Plus Alternatives
Banner Display Thumbnail
banner-display-thumbnail
A quick, easy way to add an Responsive header Banner Display Thumbnail OR Responsive Banner Display Thumbnail inside wordpress page OR Template.
Mobile Frame
mobile-frame
Display images in a mobile device frame.
Slim Mobile Theme Switcher
slim-mobile-theme-switcher
Serve a mobile theme to phones while keeping desktops/tablets on the primary theme. Lightweight mobile theme switcher with modern device detection.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
WP Mobile Menu – The Mobile-Friendly Responsive Menu
mobile-menu
Need some help with the mobile website experience? Need an Mobile Menu plugin that keep your mobile visitors engaged?
LIQUID RWD Plus Developer Profile
9 plugins · 16K total installs
How We Detect LIQUID RWD Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/liquid-rwd-plus/js/jquery.cookie.js/wp-content/plugins/liquid-rwd-plus/js/rwd.js/liquid-rwd-plus/js/jquery.cookie.js/liquid-rwd-plus/js/rwd.jsliquid-rwd-plus/js/jquery.cookie.js?ver=liquid-rwd-plus/js/rwd.js?ver=HTML / DOM Fingerprints
wrappostboxinside recommend settings liquid_rwd_plus_toggle