
Page List Widget Security & Risk Analysis
wordpress.org/plugins/page-list-widgetThis is a widget plugin. This widget will display a list of posts/pages.
Is Page List Widget Safe to Use in 2026?
Generally Safe
Score 85/100Page List Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'page-list-widget' v1.4.0 plugin presents a mixed security posture. While the static analysis reports zero known vulnerabilities in its history and a clean slate regarding dangerous functions, SQL injection, and file operations, significant concerns arise from the output escaping. A mere 22% of outputs are properly escaped, leaving a substantial portion of user-generated or dynamic content vulnerable to cross-site scripting (XSS) attacks. The absence of any nonce or capability checks, combined with zero entry points that are protected, further exacerbates this risk, as any potential future vulnerabilities could be exploited without authentication or authorization mechanisms in place. The plugin demonstrates good practices by using prepared statements for all SQL queries, which is a strong positive. However, the lack of input validation and insufficient output sanitization creates a considerable attack surface for XSS, overshadowing the otherwise clean code signals and vulnerability history.
Key Concerns
- Insufficient output escaping
- No nonce checks
- No capability checks
Page List Widget Security Vulnerabilities
Page List Widget Code Analysis
Output Escaping
Page List Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Page List Widget Maintenance & Trust
Maintenance Signals
Community Trust
Page List Widget Alternatives
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Per Page Sidebars
per-page-sidebars
The Per Page Sidebars (PPS) plugin allows blog administrators to create a unique sidebar for each Page. No template editing is required.
Admin Dashboard Last Edits
admin-dashboard-last-edits
Easy and lightweight solution for showing the last edited posts and pages on the admin dashboard.
Query Posts
query-posts
A WordPress widget that gives you unlimited control over showing posts and pages.
Per Page Widgets
per-page-widgets
Control widget areas on a per-page / per-post basis.
Page List Widget Developer Profile
1 plugin · 400 total installs
How We Detect Page List Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-list-widget/js/page-list-widget.js/wp-content/plugins/page-list-widget/js/page-list-widget.jsHTML / DOM Fingerprints
page-list-widget-wrap<!-- Page List Widget -->data-post-typedata-numberdata-sort-coldata-asc-descdata-excludedata-include+7 morePageListWidget[page_list]