Pixel Clusters Security & Risk Analysis
wordpress.org/plugins/pixel-clustersCreate beautiful, responsive post clusters with shortcodes or Gutenberg blocks. Display posts, categories, tags, custom post types, and WooCommerce pr …
Is Pixel Clusters Safe to Use in 2026?
Generally Safe
Score 100/100Pixel Clusters has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pixel-clusters" v2.1.1 plugin demonstrates a generally strong security posture with several good practices evident in the static analysis. Notably, it utilizes prepared statements for all SQL queries and ensures 100% of its output is properly escaped, significantly mitigating risks of SQL injection and cross-site scripting (XSS) vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further reduces the potential attack surface. Its vulnerability history is also clean, with no recorded CVEs, suggesting a track record of security awareness.
However, there are specific areas that introduce risk. The presence of two AJAX handlers that lack authentication checks presents a clear attack vector. While the taint analysis shows no critical or high-severity flows, the potential for unauthorized actions through these unprotected AJAX endpoints is a concern. The limited capability check also means that even if an AJAX call were protected by a nonce, it might not be properly authorized for the user making the request. The plugin has a moderate attack surface with 12 total entry points, and the two unprotected ones are a significant weakness.
In conclusion, "pixel-clusters" v2.1.1 is built on a solid foundation with good coding practices for SQL and output handling, and a clean vulnerability history. The primary weakness lies in the lack of authentication on two AJAX handlers, which should be addressed to fully secure the plugin. The overall security is good, but the unprotected AJAX endpoints are a notable concern.
Key Concerns
- AJAX handlers without auth checks
- Limited capability checks
Pixel Clusters Security Vulnerabilities
Pixel Clusters Code Analysis
Output Escaping
Pixel Clusters Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Pixel Clusters Maintenance & Trust
Maintenance Signals
Community Trust
Pixel Clusters Alternatives
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
SEO Auto Linker
wpa-seo-auto-linker
SEO Auto Linker assists in creating cornerstone SEO content. This is not a full replacement for SEO plugins.
Custom Recent Posts Widget
custom-recent-posts-widget
A widget to show recent posts list based on categories or tags
xili-tidy-tags
xili-tidy-tags
xili-tidy-tags is a tool for grouping tags by semantic groups or by language and for creating tidy tag clouds.
Pixel Clusters Developer Profile
2 plugins · 30 total installs
How We Detect Pixel Clusters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pixel-clusters/css/admin.css/wp-content/plugins/pixel-clusters/js/admin.js/wp-content/plugins/pixel-clusters/css/pixel-clusters.css/wp-content/plugins/pixel-clusters/js/cluster.js/wp-content/plugins/pixel-clusters/js/admin.js/wp-content/plugins/pixel-clusters/js/cluster.jspixel-clusters/css/admin.css?ver=pixel-clusters/js/admin.js?ver=pixel-clusters/css/pixel-clusters.css?ver=pixel-clusters/js/cluster.js?ver=HTML / DOM Fingerprints
window.pixelClustersAdminwindow.pixelClustersFront/wp-json/pixel-cluster/v1/preview/wp-json/pixel-cluster/v1/taxonomies/wp-json/pixel-cluster/v1/terms[cluster