
Pocket Widget Security & Risk Analysis
wordpress.org/plugins/pocket-widgetA Wordpress widget to show your Pocket collection.
Is Pocket Widget Safe to Use in 2026?
Use With Caution
Score 64/100Pocket Widget has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "pocket-widget" plugin v0.1.3 presents a mixed security posture. While the static analysis indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events lacking authentication or permission checks, there are notable concerns within the codebase itself. Specifically, the presence of a single SQL query that does not utilize prepared statements is a significant risk, potentially exposing the site to SQL injection vulnerabilities. Furthermore, the low percentage of properly escaped output (9%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, especially given that the plugin has a history of XSS-related CVEs.
The plugin's vulnerability history, including a recent unpatched medium severity CVE related to XSS, exacerbates these concerns. This pattern indicates that the developers may struggle with secure coding practices, particularly in sanitizing user input and preventing the injection of malicious scripts. While the absence of a large, unprotected attack surface is a positive, the internal code quality issues and the ongoing unpatched vulnerability create a substantial risk. The overall conclusion is that while the plugin's direct exposure points are limited, the internal code quality and historical vulnerability suggest a need for significant improvement to ensure a secure state.
Key Concerns
- Unpatched CVE exists
- SQL query without prepared statements
- Low percentage of properly escaped output
- No capability checks
- Flows with unsanitized paths
Pocket Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Pocket Widget <= 0.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting
Pocket Widget Release Timeline
Pocket Widget Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Pocket Widget Attack Surface
WordPress Hooks 5
Maintenance & Trust
Pocket Widget Maintenance & Trust
Maintenance Signals
Community Trust
Pocket Widget Alternatives
Pocket WP
pocket-wp
Pocket WP allows you to embed your Pocket links into a WordPress page or post via a shortcode or a widget.
WordsTree Pocket Navigator
wt-pocket-navigator
The plugin to make available for you, while you write, your Pocket favorites.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Pocket Widget Developer Profile
3 plugins · 30 total installs
How We Detect Pocket Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pocket-widget/js/pocketwidget.js/wp-content/plugins/pocket-widget/js/pocketwidget.jsHTML / DOM Fingerprints
wp-pocketwidget-settingsid="reset_consumer_key"id="show_access_token"id="revoke_access_token"