
myWidget recommendations Security & Risk Analysis
wordpress.org/plugins/mywidget-recommendationsmyWidget: Widget with personalized recommendations for increasing user metrics.
Is myWidget recommendations Safe to Use in 2026?
Generally Safe
Score 100/100myWidget recommendations has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mywidget-recommendations" v1.0.4 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, has no file operations, and makes no external HTTP requests. The lack of known CVEs and a clean vulnerability history are also positive indicators of general code quality and diligence regarding security patches.
However, several critical security concerns are present. The use of the deprecated `create_function` is a significant risk, as it can be exploited for remote code execution if not handled with extreme care, especially given the lack of capability checks and nonce checks. Furthermore, while the majority of output is escaped, a notable percentage (26%) remains unescaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if the data originates from an untrusted source.
While the attack surface appears minimal, the presence of the dangerous `create_function` function, coupled with the absence of any authorization or nonce checks on any entry points (even though there are none reported), presents a latent risk. If an entry point were to be discovered or added in the future, it might be susceptible to attack without proper safeguards. The plugin's strengths lie in its database query security and external interaction avoidance, but its weaknesses are tied to outdated coding practices and potential for XSS.
Key Concerns
- Dangerous function: create_function used
- Unescaped output found (26%)
- No nonce checks implemented
- No capability checks implemented
myWidget recommendations Security Vulnerabilities
myWidget recommendations Code Analysis
Dangerous Functions Found
Output Escaping
myWidget recommendations Attack Surface
WordPress Hooks 9
Maintenance & Trust
myWidget recommendations Maintenance & Trust
Maintenance Signals
Community Trust
myWidget recommendations Alternatives
Taboola
taboola
Use the Taboola plugin to generate revenue from native ads and drive engagement with editorial content.
PubExchange
pubexchange
Use the PubExchange widget to promote content from the sites that you have partnered with through PubExchange.com
Primal for WordPress
primal-for-wp
Engage your readers with great content that expresses your interests!
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
myWidget recommendations Developer Profile
1 plugin · 10 total installs
How We Detect myWidget recommendations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mywidget-recommendations/admin/css/mywidget-recommendations-admin.css/wp-content/plugins/mywidget-recommendations/admin/js/mywidget-recommendations-admin.jsmywidget-recommendations/admin/css/mywidget-recommendations-admin.css?ver=mywidget-recommendations/admin/js/mywidget-recommendations-admin.js?ver=HTML / DOM Fingerprints
data-uidmywidget_recommendations_admin