
PHP-Widgetify Security & Risk Analysis
wordpress.org/plugins/php-widgetifyExecute HTML, Text or PHP fast and easy with this Widgetify-widget.
Is PHP-Widgetify Safe to Use in 2026?
Generally Safe
Score 85/100PHP-Widgetify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of php-widgetify v1.0 reveals a mixed security posture. On one hand, the plugin demonstrates good practices by having no observed AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests. However, the presence of one instance of the `create_function` dangerous function is a significant concern. This function is known to be insecure and can lead to code injection vulnerabilities if user-supplied data is used within it without proper sanitization.
The output escaping percentage is notably low at 14%, indicating a high risk of cross-site scripting (XSS) vulnerabilities where dynamic content is displayed to users without sufficient sanitization. The absence of nonce checks on any entry points, coupled with only one capability check, suggests that authentication and authorization might be weak for any code that does execute.
The vulnerability history for php-widgetify is clean, with zero recorded CVEs. This absence of past vulnerabilities is positive, but it does not negate the inherent risks identified in the static analysis. The low output escaping and the presence of `create_function` are direct code-level concerns that require attention, regardless of historical exploits. Overall, while the plugin has a minimal attack surface, the identified code quality issues, particularly concerning output escaping and the use of a dangerous function, present clear security weaknesses that should be addressed.
Key Concerns
- Use of dangerous function 'create_function'
- Low output escaping percentage (14%)
- No nonce checks on entry points
PHP-Widgetify Security Vulnerabilities
PHP-Widgetify Code Analysis
Dangerous Functions Found
Output Escaping
PHP-Widgetify Attack Surface
WordPress Hooks 1
Maintenance & Trust
PHP-Widgetify Maintenance & Trust
Maintenance Signals
Community Trust
PHP-Widgetify Alternatives
Reve Dynamic Widget
reve-dynamic-widget
Add any text, HTML, CSS, Javascript and/or PHP code, and show it in the pages you want.
Code Widget
code-widget
Code widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
widget text class ats
class-widget-ats-text
Простой текстовый виджет позволит вам запускать PHP и шорткод (shortcode) сразу после активации плагина widget text class ats (WordPress виджет по умо …
Safe PHP Code Widget
safe-php-code-widget
Adds a secure and simple widget in which you can use PHP and JavaScript code. Also you can use unfiltered HTML or just Text. Admin Use Only.
Rich Text Editor
richtexteditor
This plugin integrates your Wordpress with RichTextEditor - the most powerful online wysiwyg content editor.
PHP-Widgetify Developer Profile
1 plugin · 40 total installs
How We Detect PHP-Widgetify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
execphpwidget