
List Sub Pages Security & Risk Analysis
wordpress.org/plugins/list-sub-pagesThis is a WordPress plugin for listing your subpages(childpages) for the current page which is being displayed.
Is List Sub Pages Safe to Use in 2026?
Generally Safe
Score 99/100List Sub Pages has a strong security track record. Known vulnerabilities have been patched promptly.
The list-sub-pages plugin v1.0.8 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and proper output escaping for all identified outputs are significant strengths. Furthermore, the plugin has a single identified capability check, indicating an awareness of access control, and no file operations or external HTTP requests, which reduces common attack vectors. The lack of any identified taint flows further reinforces the good practices observed in the code analysis.
However, the plugin's vulnerability history presents a concern. A past medium severity Cross-Site Scripting (XSS) vulnerability, though currently patched, indicates a potential for input sanitization issues. The absence of nonce checks across its limited entry points, particularly the single shortcode, is a notable weakness. While there are no unprotected entry points or critical taint flows, the past XSS vulnerability, coupled with the missing nonce checks, suggests that input handling, especially for the shortcode, warrants careful scrutiny to prevent future issues.
In conclusion, the list-sub-pages plugin has implemented several robust security measures. The code analysis shows good practices in crucial areas like SQL and output handling. Nevertheless, the historical vulnerability and the absence of nonce checks on its shortcode are areas that could be improved to further harden its security posture and mitigate potential risks.
Key Concerns
- Past medium severity XSS vulnerability
- No nonce checks on shortcodes
List Sub Pages Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
List Subpages <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter
List Sub Pages Code Analysis
Output Escaping
List Sub Pages Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
List Sub Pages Maintenance & Trust
Maintenance Signals
Community Trust
List Sub Pages Alternatives
Page-list
page-list
[pagelist], [subpages], [siblings] and [pagelist_ext] shortcodes
CC Child Pages
cc-child-pages
Display WordPress child pages in a responsive grid or list using a shortcode, Gutenberg block or Elementor widget.
Auto Submenu
auto-submenu
Dynamic menus: Add a page to your menu and then let WordPress automatically add the child pages.
Multipage
sgr-nextpage-titles
Order your posts in subpages: multipage posts will have a table of contents linking single subpages with their titles.
Subpage Listing
subpage-listing
Allows you to display a list of the child pages of the currently viewed page.
List Sub Pages Developer Profile
13 plugins · 5K total installs
How We Detect List Sub Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/list-sub-pages/js/install_plugin_lsp.js/wp-content/plugins/list-sub-pages/js/install_plugin_lsp.jslist-sub-pages/js/install_plugin_lsp.js?ver=HTML / DOM Fingerprints
ls_sub_pagessub-page[sub_page]