
Page Whitelists Security & Risk Analysis
wordpress.org/plugins/page-whitelistsNOTICE: This plugin is no longer in active development. Limit user access only to selected ("whitelisted") pages by creating whitelists and …
Is Page Whitelists Safe to Use in 2026?
Generally Safe
Score 85/100Page Whitelists has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'page-whitelists' v4.0.2 plugin exhibits a mixed security posture. While it benefits from a lack of recorded vulnerabilities and a generally good use of prepared statements for SQL queries, several concerning aspects are present in the static analysis. A significant weakness lies in its attack surface, with one of the three AJAX handlers lacking authentication checks, opening it up to potential unauthorized access or manipulation.
Furthermore, the taint analysis reveals three high-severity flows with unsanitized paths, indicating potential vulnerabilities where user-supplied data could be misused. The complete absence of proper output escaping across all identified outputs is a critical concern, as it suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of file operations, even if only one, coupled with the lack of proper escaping, warrants careful consideration.
Despite the clean vulnerability history, which is a positive indicator, the static analysis findings present clear and actionable risks. The combination of an unprotected AJAX endpoint and the prevalent lack of output escaping creates a significant security concern that could be exploited. Therefore, while the plugin has demonstrated a history of stability, these newly identified weaknesses require immediate attention and remediation.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized taint flows (3)
- No output escaping on any output
- File operations present
Page Whitelists Security Vulnerabilities
Page Whitelists Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Page Whitelists Attack Surface
AJAX Handlers 3
WordPress Hooks 21
Maintenance & Trust
Page Whitelists Maintenance & Trust
Maintenance Signals
Community Trust
Page Whitelists Alternatives
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
WP Fastest Cache – WordPress Cache Plugin
wp-fastest-cache
The simplest and fastest WP Cache system
Autoptimize
autoptimize
Autoptimize speeds up your website by optimizing JS, CSS, images (incl. lazy-load), HTML and Google Fonts, asyncing JS, removing emoji cruft and more.
W3 Total Cache
w3-total-cache
Search Engine (SEO) & Performance Optimization (WPO) via caching. Integrated caching: CDN, Page, Minify, Object, Fragment, Database support.
Page Whitelists Developer Profile
1 plugin · 70 total installs
How We Detect Page Whitelists
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/page-whitelists/assets/css/page-whitelists-admin.css/wp-content/plugins/page-whitelists/assets/js/page-whitelists-admin.js/wp-content/plugins/page-whitelists/assets/js/page-whitelists-admin.jspage-whitelists/assets/css/page-whitelists-admin.css?ver=page-whitelists/assets/js/page-whitelists-admin.js?ver=HTML / DOM Fingerprints
wlist-settings-wrap<!-- BEGIN Page Whitelists Metabox --><!-- END Page Whitelists Metabox -->name="wlist_settings[strict_as_default]"name="wlist_settings[filter_all_listings]"id="wl_strict_as_default"id="wl_filter_all_listings"id="wlist-metabox"id="wlist_onpage_edit"wp_lists_ajax_obj