
Multisite Directory Security & Risk Analysis
wordpress.org/plugins/multisite-directoryAdd a browseable, flexible directory of the sites in a WP Multisite network. Each subsite gets its own page.
Is Multisite Directory Safe to Use in 2026?
Generally Safe
Score 85/100Multisite Directory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The multisite-directory plugin exhibits a generally positive security posture, with no identified vulnerabilities in its history and no critical findings in the static analysis. The absence of known CVEs and the plugin's clean vulnerability record are strong indicators of ongoing security maintenance and good development practices. The static analysis also reveals a low attack surface, with all identified entry points (shortcodes) not explicitly requiring authentication checks, which is a positive sign. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for its single SQL query and largely escaping output, although there's room for improvement in the latter.
However, several areas warrant attention. The complete lack of nonce checks and capability checks across all entry points is a significant concern. While the static analysis found no unprotected entry points, this could be a limitation of the analysis itself, or it might mean that the shortcode relies on implicit WordPress checks or sanitization that isn't immediately obvious. The fact that only 50% of output is properly escaped suggests a potential for cross-site scripting (XSS) vulnerabilities, particularly if the unescaped outputs handle user-supplied data. Without proper nonce and capability checks, even seemingly benign shortcodes could be leveraged in conjunction with XSS to perform unauthorized actions. The absence of taint analysis results is also noteworthy; while it might indicate no issues, it could also mean the analysis couldn't be performed effectively for this plugin's code.
Key Concerns
- 0 Nonce checks on entry points
- 0 Capability checks on entry points
- 50% of output not properly escaped
- No taint analysis results available
Multisite Directory Security Vulnerabilities
Multisite Directory Code Analysis
SQL Query Safety
Output Escaping
Multisite Directory Attack Surface
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Multisite Directory Maintenance & Trust
Maintenance Signals
Community Trust
Multisite Directory Alternatives
WP Over Network
wp-over-network
Add ability to get posts from over your network sites. Supports widget, shortcode, and customizable original function.
Multisite Post Cloner
multisite-post-cloner
Multisite Post Cloner allows you to clone posts and pages across sites in your WordPress multisite network.
Multisite Taxonomy Widget
multisite-taxonomy-widget
List the latest posts of a specific taxonomy from your blog-network.
Toggle Admin Bar Menu
toggle-admin-bar-menu
Replaces the WordPress admin bar menu with a compact menu icon. Clicking the icon toggles the visibility of the full admin bar.
Multisite Network Repost
multisite-network-repost
Repost your stories to selected sites in the multisite network, preserving attachments, custom fields, categories, tags etc.
Multisite Directory Developer Profile
13 plugins · 2K total installs
How We Detect Multisite Directory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multisite-directory/vendor/leaflet/dist/leaflet.css/wp-content/plugins/multisite-directory/vendor/leaflet/dist/leaflet.jsHTML / DOM Fingerprints
name="multisite-directory-auto-update-entry-title"