
Picker Security & Risk Analysis
wordpress.org/plugins/pickerPicker is a simple and flexible plugin which allow users to choose a specific post inside admin widgets page and display it in their site frontend.
Is Picker Safe to Use in 2026?
Generally Safe
Score 85/100Picker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "picker" plugin v1.1.6 presents a mixed security posture. While the plugin demonstrates good practices in its handling of SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerability history, significant concerns arise from its attack surface and output escaping. The presence of two AJAX handlers with no authentication checks creates a considerable risk, as these entry points are open to unauthorized access and potential manipulation. The taint analysis indicates two flows with unsanitized paths, which, although not flagged as critical or high severity in this analysis, warrant attention. The low percentage of properly escaped output (49%) is another major concern, suggesting a high likelihood of cross-site scripting (XSS) vulnerabilities. In conclusion, the plugin's lack of vulnerability history and secure SQL practices are positive, but the unprotected AJAX endpoints and widespread unescaped output expose it to significant risks.
Key Concerns
- AJAX handlers without auth checks
- Unsanitized paths in taint analysis
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
Picker Security Vulnerabilities
Picker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Picker Attack Surface
AJAX Handlers 2
WordPress Hooks 11
Maintenance & Trust
Picker Maintenance & Trust
Maintenance Signals
Community Trust
Picker Alternatives
Simple Pregnancy Calculator
simple-pregnancy-calculator
Simple Pregnancy Calculator lets you add a datepicher in the page or in the widget area of your site.
Date Time Picker for Contact Form 7
date-time-picker-for-contact-form-7
This plugin enables Contact Form 7 text field into a Date picker, Time picker or Date Time picker by using CSS class.
Availability Datepicker – Booking Calendar for Contact Form 7 – Input WP
date-time-picker-field
Availability datepicker & booking calendar for any form. Configure business hours, time slots, date overrides and a booking window.
Desert Companion
desert-companion
Desert Companion Enhances Desert Themes with additional functionality.
Error Log Monitor
error-log-monitor
Adds a Dashboard widget that displays the latest messages from your PHP error log. It can also send logged errors to email.
Picker Developer Profile
4 plugins · 1K total installs
How We Detect Picker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/picker/assets/css/picker.css/wp-content/plugins/picker/assets/js/picker.js/wp-content/plugins/picker/assets/js/picker.jspicker/assets/css/picker.css?ver=picker/assets/js/picker.js?ver=HTML / DOM Fingerprints
picker-widgetdata-pkr-valuePicker