
Page Template Column Security & Risk Analysis
wordpress.org/plugins/page-template-columnAdds a column to the pages table in WP Admin > Pages displaying the page template used.
Is Page Template Column Safe to Use in 2026?
Generally Safe
Score 85/100Page Template Column has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "page-template-column" plugin v1.0.0 exhibits a very limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. This suggests a potentially low risk of direct exploitation through common WordPress entry points. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are excellent security practices that mitigate several common vulnerability classes.
However, the static analysis did reveal a significant concern: 100% of identified outputs are not properly escaped. This lack of output sanitization presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. If user-supplied data or data originating from external sources is displayed on the frontend without proper escaping, an attacker could inject malicious scripts. The plugin's history of zero known CVEs and no recorded vulnerabilities is a positive sign, suggesting a generally well-maintained codebase. However, the lack of any capability checks or nonce checks, combined with the unescaped output, indicates that while the plugin might not have been targeted or exploited historically, it is susceptible to certain types of attacks.
In conclusion, while the "page-template-column" plugin has strengths in its limited attack surface and adherence to secure SQL practices, the critical finding of unescaped output poses a substantial risk. The absence of nonce and capability checks further weakens its security posture. The plugin's clean vulnerability history is positive but does not negate the identified security flaws. It is strongly recommended that the unescaped output issue be addressed promptly to mitigate potential XSS vulnerabilities.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Page Template Column Security Vulnerabilities
Page Template Column Code Analysis
Output Escaping
Page Template Column Attack Surface
WordPress Hooks 3
Maintenance & Trust
Page Template Column Maintenance & Trust
Maintenance Signals
Community Trust
Page Template Column Alternatives
Admin Columns
codepress-admin-columns
Customise columns on the administration screens for post(types), pages, media, comments, links and users with an easy to use drag-and-drop interface.
Admin Columns for ACF Fields
admin-columns-for-acf-fields
Allows you to enable columns for your ACF fields in post and taxonomy overviews (e.g. "All Posts") in the Wordpress admin backend.
WP Adminify – White Label WordPress, Admin Menu Editor, Login Customizer
adminify
Transform your WordPress admin into a fully white-labeled, organized client dashboard. Customize, Dark mode, Secure, Boost productivity, and more.
Admin Slug Column
admin-slug-column
Adds a URL path column to all admin post type edit screens. Works with posts, pages, and any custom post type including WooCommerce products.
Advanced Post Manager
advanced-post-manager
Turbo charge your posts admin for any custom post type with sortable filters and columns, and auto-registration of metaboxes.
Page Template Column Developer Profile
2 plugins · 100 total installs
How We Detect Page Template Column
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-template-column/css/page-template-column.css/wp-content/plugins/page-template-column/js/page-template-column.js/wp-content/plugins/page-template-column/js/page-template-column.jspage-template-column/css/page-template-column.css?ver=1.0.0page-template-column/js/page-template-column.js?ver=1.0.0