
Multisite Widgets Security & Risk Analysis
wordpress.org/plugins/mu-widgetsExtends the standard WordPress widgets to be able to run on another blog on the site.
Is Multisite Widgets Safe to Use in 2026?
Generally Safe
Score 85/100Multisite Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mu-widgets" plugin, version 1.2.48f, exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and all detected SQL queries utilize prepared statements, which is a significant strength. The static analysis also shows a zero-tolerance for critical or high severity taint flows, indicating that potentially malicious data is not being processed in a high-risk manner concerning paths. The plugin also doesn't expose a large attack surface through typical WordPress entry points like AJAX handlers, REST API routes, or shortcodes, and there are no scheduled cron events. However, there are several concerning signals. The absence of nonce checks and capability checks across its code is a major security gap. This means that any function that could potentially be invoked, even if not directly exposed as an entry point, lacks crucial authentication and authorization controls, making it susceptible to CSRF attacks or unauthorized actions if discovered. Furthermore, the fact that 100% of the 12 output operations are not properly escaped presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site's output. The use of dangerous functions like `unserialize` also raises concerns, as unserializing untrusted data can lead to object injection vulnerabilities. The presence of file operations and an external HTTP request, without any explicit security checks, also warrants further investigation.
Key Concerns
- No nonce checks detected
- No capability checks detected
- 100% of outputs are unescaped
- Dangerous function: unserialize
- Dangerous function: set_time_limit
- File operations present without context
- External HTTP request present without context
- Bundled library TinyMCE
Multisite Widgets Security Vulnerabilities
Multisite Widgets Release Timeline
Multisite Widgets Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Multisite Widgets Attack Surface
WordPress Hooks 2
Maintenance & Trust
Multisite Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Multisite Widgets Alternatives
Reorder My Sites
reorder-my-sites
For WordPress Multisite. Reorders the My Sites dropdown menu in the Admin Bar alphabetically. It keeps the main blog at the top.
Multisite Blog Id's
multisite-blog-ids
Easily find the Site Id for Multisite blogs.
BNS Corner Logo
bns-corner-logo
Widget to display a logo; or, used as a plugin displays image fixed in one of the four corners.
Counter Ecl
counter-ecl
Making WordPress web counter widget and cookie Law.
WP Over Network
wp-over-network
Add ability to get posts from over your network sites. Supports widget, shortcode, and customizable original function.
Multisite Widgets Developer Profile
6 plugins · 60 total installs
How We Detect Multisite Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mu-widgets/library/base/public/css/images.css/wp-content/plugins/mu-widgets/library/base/public/css/admin.css/wp-content/plugins/mu-widgets/library/base/public/css/front.css/wp-content/plugins/mu-widgets/library/base/public/css/common.css/wp-content/plugins/mu-widgets/library/base/public/js/script.js/wp-content/plugins/mu-widgets/library/base/public/js/script.jsmu-widgets/library/base/public/css/images.css?ver=mu-widgets/library/base/public/css/admin.css?ver=mu-widgets/library/base/public/css/front.css?ver=mu-widgets/library/base/public/css/common.css?ver=mu-widgets/library/base/public/js/script.js?ver=HTML / DOM Fingerprints
v48fv_16x16_info??document??Default actions of all typesRoutines used by the default actionsdefault sub menu itemsdata-tinymcedata-plugin-namev48fv_data