
Page Keys Security & Risk Analysis
wordpress.org/plugins/page-keysRegister page keys, assign WordPress pages to them, and access each of these pages by its individual key.
Is Page Keys Safe to Use in 2026?
Generally Safe
Score 99/100Page Keys has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'page-keys' v1.3.4 plugin exhibits a strong security posture based on the static analysis provided. The complete absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, or unescaped output suggests diligent coding practices. Furthermore, the presence of nonce and capability checks for critical operations indicates a good understanding of WordPress security principles. The plugin also avoids common attack vectors like AJAX handlers, REST API routes, shortcodes, and cron events without proper authentication or authorization, resulting in a zero-attack surface with unprotected entry points.
However, the vulnerability history presents a significant concern. The existence of one known CVE, albeit reportedly patched, and specifically a medium severity Cross-Site Scripting (XSS) vulnerability, indicates past security weaknesses. The fact that the last vulnerability was recorded in 2026-01-06 19:58:54, a future date, requires careful consideration as it might be a data anomaly or indicate a need for proactive review of upcoming security advisories. While the current analysis shows no active issues, the historical pattern suggests a potential for future vulnerabilities if development practices are not continuously maintained and reviewed.
In conclusion, the 'page-keys' plugin demonstrates commendable static security attributes. The code appears robust and follows best practices, leading to a low risk from immediate code vulnerabilities. The primary area of concern remains the historical vulnerability, which necessitates vigilance and ongoing security monitoring despite the current positive static analysis. The plugin's strengths lie in its clean code and adherence to security checks, while its weakness is highlighted by past security incidents.
Key Concerns
- Past medium severity XSS vulnerability
Page Keys Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Page Keys <= 1.3.3 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'page_key' Parameter
Page Keys Release Timeline
Page Keys Code Analysis
Output Escaping
Page Keys Attack Surface
WordPress Hooks 7
Maintenance & Trust
Page Keys Maintenance & Trust
Maintenance Signals
Community Trust
Page Keys Alternatives
Access Keys for WP Navigation Menus
wordpress-nav-menus-access-keys
Add Access Keys to WordPress 3.6 Nav menus to make your website far more accessible.
Access Keys
access-keys
Add Access Keys to Category and Page navigation menus to make your website far more accessible.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
WP Fastest Cache – WordPress Cache Plugin
wp-fastest-cache
The simplest and fastest WP Cache system
Page Keys Developer Profile
8 plugins · 2K total installs
How We Detect Page Keys
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-keys/assets/js/admin.min.js/wp-content/plugins/page-keys/assets/js/admin.js/wp-content/plugins/page-keys/assets/js/admin.min.js/wp-content/plugins/page-keys/assets/js/admin.jsHTML / DOM Fingerprints
tfPageKeysData