
LRW Widgets Bundle Security & Risk Analysis
wordpress.org/plugins/lrw-so-widgets-bundleExtends the functions of the plugin SiteOrigin Widgets with new widgets options.
Is LRW Widgets Bundle Safe to Use in 2026?
Generally Safe
Score 85/100LRW Widgets Bundle has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lrw-so-widgets-bundle plugin v1.1.3 exhibits a very low risk profile based on the provided static analysis and vulnerability history. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface, and importantly, all identified entry points appear to be protected. The code also demonstrates good security practices by using prepared statements for all SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. The lack of taint flows further suggests that sensitive data is handled securely within the plugin's scope.
While the plugin shows strengths in its limited attack surface and secure data handling for SQL, there is a notable concern regarding output escaping. With 61% of outputs properly escaped, a significant portion (39%) remains unescaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without proper sanitization. The complete absence of known vulnerabilities in its history is a positive indicator, suggesting a history of secure development or diligent patching by developers.
In conclusion, the lrw-so-widgets-bundle v1.1.3 appears to be a secure plugin with a minimal attack surface and good SQL handling. However, the unescaped output is a specific area of concern that should be addressed to further harden the plugin's security posture. Without any recorded historical vulnerabilities, the plugin's development team seems to prioritize security.
Key Concerns
- Unescaped output identified
LRW Widgets Bundle Security Vulnerabilities
LRW Widgets Bundle Code Analysis
Output Escaping
LRW Widgets Bundle Attack Surface
WordPress Hooks 5
Maintenance & Trust
LRW Widgets Bundle Maintenance & Trust
Maintenance Signals
Community Trust
LRW Widgets Bundle Alternatives
Element Bits
element-bits
Element Bits adds a growing collection of lightweight, easy-to-use widgets to Elementor page builder, helping you build beautiful pages faster.
SiteOrigin Widgets Bundle
so-widgets-bundle
Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
Social Media Share Buttons & Social Sharing Icons
ultimate-social-media-icons
Share buttons and pop up share icons for social media sharing
LRW Widgets Bundle Developer Profile
2 plugins · 310 total installs
How We Detect LRW Widgets Bundle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/js/wow.min.js/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/js/jquery.waypoints.min.js/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/js/jquery.countTo.js/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/css/lrw-counter.css/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/js/wow.min.js/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/js/jquery.waypoints.min.js/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/js/jquery.countTo.js/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/css/lrw-counter.css?ver=/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/js/wow.min.js?ver=/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/js/jquery.waypoints.min.js?ver=/wp-content/plugins/lrw-so-widgets-bundle/widgets/lrw-counter/js/jquery.countTo.js?ver=HTML / DOM Fingerprints
lrw-counter-wrapperlrw-counter-titlelrw-counter-valuelrw-counter-prefixlrw-counter-suffixdata-wow-delaydata-wow-durationdata-countdata-fromdata-todata-speed+8 moreWOWjQuery.fn.waypointsjQuery.fn.countTo