
List Plugins Security & Risk Analysis
wordpress.org/plugins/list-pluginsCreate a list of the active plugins in a page (when the shortcode [list_plugins] is found).
Is List Plugins Safe to Use in 2026?
Generally Safe
Score 85/100List Plugins has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "list-plugins" v1.4.4 plugin exhibits a concerning security posture primarily due to its significant attack surface exposed without proper authentication. With 8 unprotected AJAX handlers, the plugin presents a clear pathway for unauthorized users to trigger potentially sensitive actions or access information. The presence of the `unserialize` function is a critical red flag, as it can lead to remote code execution if improperly handled, especially when coupled with user-supplied data. While the taint analysis did not reveal critical or high severity flows, the sheer volume of unsanitized paths (10 out of 10 analyzed) suggests a lack of robust input validation and sanitization throughout the plugin's code.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This might indicate a well-written codebase in terms of known vulnerabilities or simply a lack of widespread security scrutiny. However, the strong indicators of insecure coding practices, such as the large number of unprotected entry points and the use of `unserialize`, outweigh the clean vulnerability history. The low percentage of properly escaped output and the high number of file operations, without explicit details on their nature, also contribute to a heightened risk profile. In conclusion, while the plugin appears free of documented historical vulnerabilities, the static and taint analysis findings point to significant potential weaknesses that could be exploited by attackers.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function: unserialize
- Unsanitized paths in taint analysis
- Low percentage of properly escaped output
- SQL queries without prepared statements
- No nonce checks on entry points
List Plugins Security Vulnerabilities
List Plugins Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
List Plugins Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 26
Maintenance & Trust
List Plugins Maintenance & Trust
Maintenance Signals
Community Trust
List Plugins Alternatives
Active Campaign & Contact Form 7
wpop-accf
Add Contact Form 7 Data to ActiveCampaign Contact lists.
List Images
list-images
Easy way to view and manage all images.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
YITH WooCommerce Wishlist
yith-woocommerce-wishlist
YITH WooCommerce Wishlist add all Wishlist features to your website. Needs WooCommerce to work. WooCommerce 10.6.x compatible.
WP Sitemap Page
wp-sitemap-page
Add a sitemap on any of your page using the simple shortcode [wp_sitemap_page]. Improve the SEO and navigation of your website.
List Plugins Developer Profile
14 plugins · 31K total installs
How We Detect List Plugins
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- ==================================================================================================================================================== -->