
Page In Page Security & Risk Analysis
wordpress.org/plugins/page-in-pageThis plugin helps you insert a post or page from the WP posts database table within another, bring your Facebook posts and Twitter feeds to your blog.
Is Page In Page Safe to Use in 2026?
Generally Safe
Score 85/100Page In Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "page-in-page" v2.0.3 plugin exhibits a mixed security posture. On the positive side, there are no known vulnerabilities in its history, and the static analysis reveals no dangerous functions, no raw SQL queries, and no taint flows indicating critical or high-severity issues. The plugin also has a limited attack surface with no unprotected entry points identified.
However, significant concerns arise from the code signals. The extremely low percentage of properly escaped output (6%) is a major red flag. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, where user-supplied data could be rendered unsafely, allowing attackers to inject malicious scripts. The presence of file operations and external HTTP requests, while not inherently insecure, requires careful scrutiny to ensure they are handled with proper sanitization and validation to prevent path traversal or unintended data leakage.
In conclusion, while the absence of known vulnerabilities and critical code flaws is encouraging, the poor output escaping practices present a substantial security risk. This weakness needs to be addressed to improve the plugin's overall security.
Key Concerns
- Poor output escaping practices
- File operations present
- External HTTP requests present
Page In Page Security Vulnerabilities
Page In Page Code Analysis
Output Escaping
Page In Page Attack Surface
Shortcodes 4
WordPress Hooks 5
Maintenance & Trust
Page In Page Maintenance & Trust
Maintenance Signals
Community Trust
Page In Page Alternatives
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Disable Author Pages
disable-author-pages
Disable the author pages
Login Form Anywhere
login-form-anywhere
Allow admin to show login from anywhere in Wordpress.
Bloglovin Follow
bloglovin-follow
Allows the user to display their Bloglovin Follow button in posts/pages/ custom post types or in a widget.
Newscodes – News, Magazine and Blog Elements – Free Version
newscodes-news-magazine-and-blog-elements
Welcome to the future of your posts! Newscodes will revolutionize how you use and display your posts and improve the way your visitors interact with y …
Page In Page Developer Profile
2 plugins · 300 total installs
How We Detect Page In Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-in-page/assets/css/page-in-page.css/wp-content/plugins/page-in-page/assets/js/page-in-page.js/wp-content/plugins/page-in-page/assets/js/page-in-page.jspage-in-page/assets/css/page-in-page.css?ver=page-in-page/assets/js/page-in-page.js?ver=HTML / DOM Fingerprints
twl-page-in-pagetwl-page-in-page-titletwl-page-in-page-imagetwl-page-in-page-contenttwl-page-in-page-textdata-twl-page-in-page-idTWL_Page_IN_Page_PageTWL_Page_IN_Page_WidgetTWL_Page_In_Page_VarsTWL_PIP_Config[twl_page_in[twl_page_in_wp[twl_page_in_fb[twl_page_in_tw