
Plugin Display Page Security & Risk Analysis
wordpress.org/plugins/plugin-display-pageInstall and activate the plugin Click 'Plugin Pages' in the admin menu Fill in the inputs and click publish Click View Post to check out you …
Is Plugin Display Page Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Display Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "plugin-display-page" v1.0 exhibits a strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the analysis indicates no dangerous functions are used, all SQL queries employ prepared statements, and there are no file operations or external HTTP requests, which are all positive security indicators. The presence of a nonce check and a capability check, albeit only one each, suggests an awareness of secure coding practices.
However, a notable concern arises from the low percentage of properly escaped outputs (12%). This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed on the frontend. While the taint analysis shows no identified unsanitized flows, this might be due to the limited scope of the analysis or the plugin's functionality not exposing such flows. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign but does not guarantee future safety, especially given the output escaping issue.
In conclusion, the plugin has a solid foundation with a minimal attack surface and the correct use of prepared statements. The primary weakness lies in the insufficient output escaping, which presents a clear risk. While the lack of past vulnerabilities is reassuring, it's crucial to address the output escaping before considering the plugin fully secure.
Key Concerns
- Insufficient output escaping
Plugin Display Page Security Vulnerabilities
Plugin Display Page Code Analysis
Output Escaping
Plugin Display Page Attack Surface
WordPress Hooks 8
Maintenance & Trust
Plugin Display Page Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Display Page Alternatives
WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder
wdesignkit
3000+ Elementor Templates, Gutenberg Templates, Widgets Builder for Elementor, Gutenberg & Bricks, Cloud Workspace & Figma Files, 160+ Widgets Library
Event Single Page Builder For The Events Calendar
event-page-templates-addon-for-the-events-calendar
The Events Calendar addon to create custom single event page templates and replace the default event single page layout with your own branded design.
Blank
blank
A completely blank custom page template to build on.
Display custom fields in the frontend – Post and User Profile Fields
shortcode-to-display-post-and-user-data
Display post and user custom fields data anywhere on the frontend using a shortcode, including advanced custom fields (ACF) fields.
WP Page Templates
custom-page-templates-by-vegacorp
Create full width pages, add left or right sidebars, add above or below content sidebars.
Plugin Display Page Developer Profile
2 plugins · 20 total installs
How We Detect Plugin Display Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plugin-display-page/css/plugindisplaypg.css/wp-content/plugins/plugin-display-page/css/owl.carousel.css/wp-content/plugins/plugin-display-page/css/owl.theme.default.min.css/wp-content/plugins/plugin-display-page/js/plugindisplaypg.js/wp-content/plugins/plugin-display-page/js/owl.carousel.min.js/wp-content/plugins/plugin-display-page/js/plugindisplaypg.js/wp-content/plugins/plugin-display-page/js/owl.carousel.min.jsHTML / DOM Fingerprints
id="pdpg_plugin_name"name="pdpg_plugin_name"id="pdpg_plugin_images"name="pdpg_plugin_images"id="pdpg_plugin_contributors"name="pdpg_plugin_contributors"+20 more