
Page Modified Security & Risk Analysis
wordpress.org/plugins/page-modifiedDisplay the results of your Page Modified crawls right within your WordPress Admin.
Is Page Modified Safe to Use in 2026?
Generally Safe
Score 85/100Page Modified has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "page-modified" plugin v1.0.4 exhibits a generally good security posture, with a notable absence of known vulnerabilities and a clean taint analysis. The plugin correctly utilizes prepared statements for all its SQL queries, which is a critical security best practice. It also demonstrates some level of capability checks, indicating an awareness of WordPress's permission system.
However, there are significant concerns regarding output escaping. With only 6% of outputs properly escaped out of 17 total, this plugin presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. An attacker could potentially inject malicious scripts through user-supplied data that is displayed without proper sanitization. The lack of nonce checks, especially if there were any AJAX handlers (though none were detected), is also a potential area of weakness that could be exploited in conjunction with other vulnerabilities.
Given the clean vulnerability history, it's possible the plugin developers have not encountered security issues or have addressed them thoroughly in the past. However, the current static analysis highlights a critical oversight in output escaping that needs immediate attention. The plugin's strengths lie in its SQL handling and lack of known CVEs, but the significant weakness in output sanitization overshadows these positives and poses a substantial risk.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks found
Page Modified Security Vulnerabilities
Page Modified Code Analysis
Output Escaping
Page Modified Attack Surface
WordPress Hooks 5
Maintenance & Trust
Page Modified Maintenance & Trust
Maintenance Signals
Community Trust
Page Modified Alternatives
Email Address Encoder
email-address-encoder
A lightweight plugin that protects email addresses from email-harvesting robots, by encoding them into decimal and hexadecimal entities.
Robots.txt Editor
robots-txt-editor
Robots.txt for WordPress
Last Modified Timestamp
last-modified-timestamp
Adds the last modified time to the admin interface as well as a [last-modified] shortcode to use on the front-end.
Better Robots.txt – AI-Ready Crawl Control & Bot Governance
better-robots-txt
Replace the default WordPress robots.txt workflow with a smarter, structured version you can preview before publishing, with Free, Pro, and Premium ed …
Spider Analyser – WordPress搜索引擎蜘蛛分析插件
spider-analyser
Spider Analyser是一款用于跟踪WordPress网站各种搜索引擎蜘蛛爬行日志的插件,并进行详细的蜘蛛爬行数据统计、蜘蛛行为分析、蜘蛛爬取分析及伪蜘蛛拦截等。
Page Modified Developer Profile
9 plugins · 860 total installs
How We Detect Page Modified
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-modified/assets/css/admin.csshttps://cdnjs.cloudflare.com/ajax/libs/Chart.js/2.7.1/Chart.bundle.min.jspage-modified/assets/css/admin.css?ver=