
My Sites Widget Security & Risk Analysis
wordpress.org/plugins/my-sites-widgetA widget that displays a list of sites that the current user has access to.
Is My Sites Widget Safe to Use in 2026?
Generally Safe
Score 85/100My Sites Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'my-sites-widget' plugin v1.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code demonstrates good practices regarding SQL queries, with 100% utilizing prepared statements, and a complete lack of dangerous functions or file operations. This suggests a solid foundation in secure coding principles for these areas.
However, a notable concern arises from the output escaping. With only 33% of the total outputs properly escaped, there's a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data displayed without proper sanitization could be exploited. The lack of nonce checks and capability checks, while potentially mitigated by the limited attack surface, represents a missed opportunity for robust authentication and authorization, especially if new entry points were introduced in future versions or if the limited scope changes. The vulnerability history is clean, indicating a lack of previously exploited weaknesses, which is a strong positive. Overall, the plugin is strong in its limited scope and SQL handling, but the unescaped output is a critical area needing immediate attention.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
My Sites Widget Security Vulnerabilities
My Sites Widget Code Analysis
Output Escaping
My Sites Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
My Sites Widget Maintenance & Trust
Maintenance Signals
Community Trust
My Sites Widget Alternatives
WPMS Sidebar Login Widget
wpms-sidebar-login-widget
Adds a sidebar widget to the main site of a WPMU/WPMS install.
Multisite Dashboard Broadcast
multisite-dashboard-broadcast
Place a widget on top of every site's dashboard under the same Multisite installation, containing whatever content the Super Admin writes.
Bellows Accordion Menu
bellows-accordion-menu
A flexible and robust accordion menu plugin
Collapsing Categories
collapsing-categories
Adds a widget which uses Javascript to dynamically expand or collapse the set of posts for each category.
Custom Menu Wizard Widget
custom-menu-wizard
Show branches or levels of your menu in a widget, or in content using a shortcode, with full customisation.
My Sites Widget Developer Profile
20 plugins · 28K total installs
How We Detect My Sites Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_other_sites