
Plugins List Security & Risk Analysis
wordpress.org/plugins/plugins-listAllows you to insert a list of the Wordpress plugins you are using into any post/page.
Is Plugins List Safe to Use in 2026?
Generally Safe
Score 100/100Plugins List has a strong security track record. Known vulnerabilities have been patched promptly.
The "plugins-list" v2.7 plugin exhibits a generally positive security posture based on static analysis. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and properly escaped output are strong indicators of good coding practices. Furthermore, the lack of file operations and external HTTP requests reduces potential attack vectors. The limited attack surface, consisting of only two shortcodes and no AJAX handlers or REST API routes, further contributes to its security. However, the vulnerability history is a significant concern. The plugin has a known CVE, specifically a medium-severity Cross-Site Scripting (XSS) vulnerability reported in April 2023, which is currently patched. The presence of past vulnerabilities, even if patched, suggests a potential for future security weaknesses to be introduced. While current static analysis doesn't reveal immediate flaws, the historical pattern warrants vigilance and underscores the importance of consistent security auditing and updates.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Past medium severity vulnerability (XSS)
Plugins List Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Plugins List <= 2.5 - Authenticated (Author+) Stored Cross-Site Scripting via replace_plugin_list_tags
Plugins List Code Analysis
Output Escaping
Plugins List Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
Plugins List Maintenance & Trust
Maintenance Signals
Community Trust
Plugins List Alternatives
Client Showcase
client-showcase
Display your Clients with pride. This plugin displays your client's logo in a page, post using a shortcode or use the custom widget.
Author List
author-list
Display the list of authors with gravatar image and show the total number of post count on hover
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Logo Carousel – Responsive Logo Slider, Logo Showcase, and Clients Logo Gallery
logo-carousel-free
Add, display, and manage clients, partners, sponsors, and brand logos with multiple slideshows on your site. Customizable – No coding required!
Show IDs by DraftPress
wpsite-show-ids
The Show IDs plugin displays the ID of all posts, categories, pages, taxonomies, users, tags, and more.
Plugins List Developer Profile
1 plugin · 800 total installs
How We Detect Plugins List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[plugins_list][plugins_number]