
Pagelog Security & Risk Analysis
wordpress.org/plugins/pagelogThis plugin registers and displays statistics of the usage of selected wp posts/pages.
Is Pagelog Safe to Use in 2026?
Generally Safe
Score 100/100Pagelog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The pagelog plugin v1.8 demonstrates a generally strong security posture, with no known vulnerabilities or critical security issues identified in static analysis or vulnerability history. The plugin employs good security practices such as utilizing prepared statements for a significant portion of its SQL queries and properly escaping output in a majority of cases. The presence of nonce and capability checks also contributes positively to its security. The limited attack surface, consisting of a single shortcode with no immediately apparent unprotected entry points, further enhances its security profile. However, the static analysis indicates that 49% of SQL queries are not using prepared statements, which presents a potential risk for SQL injection if user input is not rigorously sanitized. Additionally, 30% of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-controllable data is displayed without adequate sanitization. While the vulnerability history is clean, these code-level risks should not be overlooked. The plugin's strengths lie in its minimal attack surface and proactive checks, but vigilance is required regarding the unescaped outputs and raw SQL queries.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
Pagelog Security Vulnerabilities
Pagelog Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Pagelog Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Pagelog Maintenance & Trust
Maintenance Signals
Community Trust
Pagelog Alternatives
Redirect 404 to Homepage (with Logging)
redirect-404-to-homepage-with-logging
Redirects 404 errors to the homepage and logs the details for review.
TwitterPad
twitterpad
TwitterPad allows twitter users to automatically collect tweets using custom search strings which are added to a specified page or as a new blog post
LogAction – Activity Logs for Admin
logaction
Track and log WordPress activities to monitor and improve your site's security and administrative tasks.
Multi-Level Page Creator
multi-level-page-creator
Create multiple parent and child pages at once using a simple admin form. Automatically generate a menu and assign pages to a selected administrator.
Quick ID Viewer
quick-id-viewer
Quickly view and copy post, page, custom post type, and taxonomy term IDs directly from the WordPress admin list view with a single click.
Pagelog Developer Profile
6 plugins · 10K total installs
How We Detect Pagelog
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
tabsid="label1"id="label2"id="label3"id="label4"id="label5"id="label6"+1 more[pagelog]