Custom & Recent Pages Widget Security & Risk Analysis

wordpress.org/plugins/onodev-recent-pages-widget

A flexible widget to display selected or latest pages, with optional pagination. Compatible with both Classic and Block Widgets.

0 active installs v1.3 PHP 7.2+ WP 5.0+ Updated Sep 28, 2025
custom-pagespages-widgetrecent-pagesselected-pages
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Custom & Recent Pages Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Custom & Recent Pages Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The onodev-recent-pages-widget plugin version 1.3 exhibits a very strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates excellent coding practices by having zero identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) that are unprotected. Furthermore, the code signals show no dangerous functions, no direct SQL queries (100% prepared statements), and an exceptionally high rate of proper output escaping (97%). The absence of file operations and external HTTP requests further minimizes potential attack vectors. The taint analysis reveals no identified flows, indicating no unsanitized data handling, which is a significant positive sign.

The vulnerability history is also pristine, with zero recorded CVEs of any severity. This lack of past vulnerabilities, combined with the current analysis showing no exploitable code patterns, suggests a well-maintained and secure plugin. The absence of common vulnerability types and recent issues further reinforces this assessment. The plugin's strengths lie in its minimal attack surface, robust data handling (prepared statements, escaping), and lack of known security flaws.

Overall, the onodev-recent-recent-pages-widget plugin v1.3 appears to be exceptionally secure. The static analysis data presents no actionable security concerns. The absence of any identified vulnerabilities in its history or current code, coupled with best practices in code hygiene, leads to a conclusion that the plugin is highly trustworthy from a security perspective. There are no evidence-backed deductions to be made based on the provided data.

Vulnerabilities
None known

Custom & Recent Pages Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Custom & Recent Pages Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
63 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped65 total outputs
Attack Surface

Custom & Recent Pages Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initonodev-recent-pages-widget.php:198
actionadmin_enqueue_scriptsonodev-recent-pages-widget.php:223
Maintenance & Trust

Custom & Recent Pages Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 28, 2025
PHP min version7.2
Downloads275

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Custom & Recent Pages Widget Developer Profile

onodev77

4 plugins · 570 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom & Recent Pages Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/onodev-recent-pages-widget/css/widget.css
Version Parameters
onodev-recent-pages-widget/css/widget.css?ver=onodev-recent-pages-widget/js/widget.js?ver=

HTML / DOM Fingerprints

CSS Classes
rpw-checkbox-wrapperrpw-checkbox-containerpage-itempage-nav
HTML Comments
<!-- <p id=" -->
Data Attributes
data-groupdata-dirdata-target
FAQ

Frequently Asked Questions about Custom & Recent Pages Widget