
Norman Advanced Archive Widget Security & Risk Analysis
wordpress.org/plugins/norman-advanced-archive-widgetNorman Advanced Archive Widget is a free replacement for the standard WordPress archive widget. Lots of customization options to satisfy your needs.
Is Norman Advanced Archive Widget Safe to Use in 2026?
Generally Safe
Score 85/100Norman Advanced Archive Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "norman-advanced-archive-widget" plugin v1.1 presents a mixed security posture. On the positive side, the plugin exhibits a robust approach to database interactions, with all SQL queries utilizing prepared statements, and there are no recorded vulnerabilities or CVEs, suggesting a history of secure development or diligent patching. The absence of file operations and external HTTP requests further limits potential attack vectors. However, the static analysis reveals significant concerns. The presence of the `create_function` function is a critical security risk, as it is deprecated and can be exploited for code injection if user-supplied data is passed to it. Furthermore, a very low percentage of output (16%) is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any nonce checks or capability checks across the entire attack surface also means that any potential entry points, even if they were present, would be exposed to unauthorized access.
Key Concerns
- Use of create_function
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Norman Advanced Archive Widget Security Vulnerabilities
Norman Advanced Archive Widget Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Norman Advanced Archive Widget Attack Surface
WordPress Hooks 3
Maintenance & Trust
Norman Advanced Archive Widget Maintenance & Trust
Maintenance Signals
Community Trust
Norman Advanced Archive Widget Alternatives
Folding Archives
folding-archives
A simple widget providing a customisable, animated dropdown menu to display archives.
Elementor Custom Skin
ele-custom-skin
Create new skins for Elementor PRO 3.x page builder. Design your own skins for Post and Post Archive Widgets using Elementor Loop Templates.
Collapsing Archives
collapsing-archives
This plugin uses Javascript to dynamically expand or collapse the set of months for each year and posts for each month in the archive listing of your …
Sitekit
sitekit
Widgets: search, archives and categories. Shortcodes: archives, bloginfo, iframe and categories.
Compact Archives
compact-archives
Displays a smart monthly archive of posts in a more compact form rather than the default long archive widget.
Norman Advanced Archive Widget Developer Profile
3 plugins · 110 total installs
How We Detect Norman Advanced Archive Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/norman-advanced-archive-widget/norman-adv-archive.phpnorman-advanced-archive-widget/norman-adv-archive.php?ver=HTML / DOM Fingerprints
norman-adv-archive-yearnorman-adv-archive-year-groupbyrelclass