
List Child Pages Shortcode Security & Risk Analysis
wordpress.org/plugins/list-child-pages-shortcodeA simple plugin to add list of child pages within the content of a parent page.
Is List Child Pages Shortcode Safe to Use in 2026?
Generally Safe
Score 99/100List Child Pages Shortcode has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'list-child-pages-shortcode' plugin version 1.4.1 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, proper use of prepared statements for SQL queries, and 100% output escaping are strong indicators of secure coding practices. Furthermore, the lack of file operations, external HTTP requests, and the total absence of taint flows with unsanitized paths suggest a well-contained and carefully written plugin. The limited attack surface, consisting of only one shortcode with no apparent vulnerabilities in its implementation according to the analysis, further contributes to its positive security profile.
However, there are a couple of areas that warrant attention. The complete absence of nonce checks and capability checks, while not immediately exploitable due to the limited attack surface and the plugin's nature, represents a missed opportunity for defense-in-depth. This means that if the single shortcode were to have a subtle vulnerability discovered in the future, it might be easier to trigger without the usual WordPress security mechanisms in place. The vulnerability history indicates a single past CVE, specifically a Cross-Site Scripting (XSS) vulnerability, which was last patched in September 2025. While this vulnerability is noted as patched, the fact that it existed at all and was of the XSS type means that future updates should be closely monitored to ensure similar issues are prevented.
In conclusion, 'list-child-pages-shortcode' v1.4.1 is a relatively secure plugin with robust handling of core security practices like SQL and output sanitization. Its main weakness lies in the omission of nonce and capability checks, which, while not a current critical flaw given the limited entry points, should be addressed for enhanced resilience against potential future threats. The past XSS vulnerability, though patched, serves as a reminder to maintain vigilance with updates.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Past XSS vulnerability
List Child Pages Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
List Child Pages Shortcode <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
List Child Pages Shortcode Release Timeline
List Child Pages Shortcode Code Analysis
Output Escaping
List Child Pages Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
List Child Pages Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
List Child Pages Shortcode Alternatives
List Pages Shortcode
list-pages-shortcode
Introduces the [list-pages], [sibling-pages] and [child-pages] shortcodes for easily displaying a list of pages within a post or page.
Protect the Children!
protect-the-children
Easily password protect the child pages/posts of a post/page that is password protected.
Child Pages Card
child-pages-card
Displays child page archives in card form.
Child Pages Tabs
child-pages-tabs
Add all the child pages Title and Content in the tabs layout to the parent page.
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
List Child Pages Shortcode Developer Profile
1 plugin · 600 total installs
How We Detect List Child Pages Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
dklcp-child-page-imagedata-parent-id<ul<li<a href="get_the_post_thumbnail