Page As Subdomain Lite Security & Risk Analysis

wordpress.org/plugins/page-as-subdomain-lite

Convert page into Subdomain, instanly convert any wordpress page to subdomain, i.e page-name.site.com

500 active installs v2.5.5 PHP + WP 3.0.1+ Updated Dec 17, 2025
pagepagesseosubdomain
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Page As Subdomain Lite Safe to Use in 2026?

Generally Safe

Score 100/100

Page As Subdomain Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "page-as-subdomain-lite" plugin v2.5.5 demonstrates a generally good security posture based on the static analysis. The absence of raw SQL queries, file operations, and critical/high taint flows is highly encouraging. The plugin also implements nonce and capability checks on its entry points, contributing to a reduced attack surface. However, a significant concern lies in the output escaping. With only 16% of 31 outputs being properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. This could allow attackers to inject malicious scripts into pages, potentially leading to session hijacking, credential theft, or defacement.

The plugin's vulnerability history is also clean, with no recorded CVEs. This, combined with the lack of critical code signals like dangerous functions or unsanitized taint flows, suggests a well-written codebase. Despite the lack of historical vulnerabilities, the output escaping issue remains a notable weakness that should be addressed to ensure a more robust security profile. The presence of external HTTP requests, while not inherently a vulnerability, can sometimes be an attack vector if not handled securely, though no specific risks are highlighted in the provided data.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Page As Subdomain Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Page As Subdomain Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
5 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

16% escaped31 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
show_menu (inc\class.PASFsubpageSubdomain.php:24)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Page As Subdomain Lite Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_install_plugin_ajaxinc\init.php:9
authwp_ajax_check_plugin_statusinc\init.php:70
WordPress Hooks 5
actioninitinc\class.PASFinitpagePlugin.php:19
filterpage_rewrite_rulesinc\class.PASFinitpagePlugin.php:27
filterpage_linkinc\class.PASFinitpagePlugin.php:28
actionadmin_menuinc\class.PASFsubpageSubdomain.php:17
filterplugin_row_metainc\init.php:95
Maintenance & Trust

Page As Subdomain Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version
Downloads46K

Community Trust

Rating72/100
Number of ratings14
Active installs500
Developer Profile

Page As Subdomain Lite Developer Profile

M. Ali Saleem

6 plugins · 690 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Page As Subdomain Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/page-as-subdomain-lite/inc/css/admin.css/wp-content/plugins/page-as-subdomain-lite/inc/js/admin.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Page As Subdomain Lite