
PHP Code Widget Security & Risk Analysis
wordpress.org/plugins/php-code-widgetLike the Text widget, but also allows working PHP code to be inserted.
Is PHP Code Widget Safe to Use in 2026?
Generally Safe
Score 85/100PHP Code Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "php-code-widget" plugin v2.4 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the analysis indicates a clean code base with no dangerous functions, no direct external HTTP requests, and the proper use of prepared statements for SQL queries. The presence of a capability check is also a positive sign. However, a significant concern arises from the output escaping, where only 14% of outputs are properly escaped. This could leave the plugin vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not sufficiently sanitized before being displayed.
Key Concerns
- Low output escaping percentage
PHP Code Widget Security Vulnerabilities
PHP Code Widget Code Analysis
Output Escaping
PHP Code Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
PHP Code Widget Maintenance & Trust
Maintenance Signals
Community Trust
PHP Code Widget Alternatives
Error Log Monitor
error-log-monitor
Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.
Code Widget
code-widget
Code widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
Widget Entries
widget-entries
Widget Entries plugin creates the Widget post-type in the administration area to make easier the edition of the text widgets, and it also register a n …
Dashboard Server Specs
dashboard-server-specs
Adds a dashboard widget displaying server specs like current PHP version.
GPP Base Hook Widgets
gpp-base-hook-widgets
Adds 12 new widget areas to the Base WordPress theme framework using its action hooks.
PHP Code Widget Developer Profile
9 plugins · 167K total installs
How We Detect PHP Code Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
execphpwidget