
List Custom Taxonomy Widget Security & Risk Analysis
wordpress.org/plugins/list-custom-taxonomy-widgetThe List Custom Taxonomy Widget is a quick and easy way to display custom taxonomies. Simply choose the taxonomy name you want to display from an auto …
Is List Custom Taxonomy Widget Safe to Use in 2026?
Generally Safe
Score 91/100List Custom Taxonomy Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The "list-custom-taxonomy-widget" plugin, version 4.2, exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding SQL injection vulnerabilities through the exclusive use of prepared statements and has no file operations or external HTTP requests, which limits its attack surface. The static analysis reports zero AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, indicating a generally secure entry point strategy.
However, the plugin's output escaping is a significant concern, with only 36% of outputs being properly escaped. This leaves a substantial portion of user-generated or dynamically generated content vulnerable to Cross-Site Scripting (XSS) attacks. The historical vulnerability data, including one past CVE related to XSS, reinforces this concern, suggesting a recurring weakness in input sanitization and output encoding. While there are no currently unpatched vulnerabilities, the pattern of past XSS issues coupled with insufficient output escaping in the current version presents a notable risk.
In conclusion, the plugin has strengths in its limited attack surface and secure database interactions. Nevertheless, the widespread lack of proper output escaping is a critical weakness that significantly elevates the risk of XSS vulnerabilities, making it a substantial concern for users.
Key Concerns
- Insufficient output escaping (36% proper)
- Past CVEs indicate recurring XSS issues
List Custom Taxonomy Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
List Custom Taxonomy Widget <= 4.1 - Authenticated (Admin+) Stored Cross-Site Scripting
List Custom Taxonomy Widget Code Analysis
Output Escaping
List Custom Taxonomy Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
List Custom Taxonomy Widget Maintenance & Trust
Maintenance Signals
Community Trust
List Custom Taxonomy Widget Alternatives
Recent Posts by Category Widget
recent-posts-by-category-widget
Just like the default Recent Posts widget except you can choose a category to pull posts from.
Categories in Hierarchical Order
categories-in-hierarchical-order
Categories in Hierarchical Order plugin maintains the hierarchical order of categories list in the Category tab under your WordPress Admin Post Editor …
NS Category Widget
ns-category-widget
A plugin to add widget for listing Categories and Taxonomies. Extending Default WordPress Category Widget.
Taxonomy Term Widget
taxonomy-term-widget
Add an advanced widget to your WordPress blog, like an extension of the Categories widget.
Featured Category Widget
category-feature
The Featured Category Widget is basically a Featured Post Widget for a category.
List Custom Taxonomy Widget Developer Profile
27 plugins · 24K total installs
How We Detect List Custom Taxonomy Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
list-custom-taxonomy-widget/style.css?ver=list-custom-taxonomy-widget/lc_taxonomy_widget.js?ver=HTML / DOM Fingerprints
list-custom-taxonomy-widgetid="lct-widget-name="lct-widget-var lc_taxonomy_widget_options =