ProGrids Widget Plugin Security & Risk Analysis

wordpress.org/plugins/progrids-widgets

ProGrids brings the products you and your followers love onto your site while keeping that natural look.

10 active installs v3.0.1 PHP + WP 3.2+ Updated Sep 3, 2014
adsaffiliatecontent-adsprogridsrelated-content
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ProGrids Widget Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

ProGrids Widget Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "progrids-widgets" v3.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the use of prepared statements for all SQL queries and a recorded lack of known vulnerabilities are positive indicators. However, there are areas of concern that warrant attention. The low percentage of properly escaped output (20%) is a significant weakness, potentially exposing the plugin to cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization. The presence of external HTTP requests, while not inherently a vulnerability, introduces a dependency on external services and could be a vector for supply chain attacks if those services are compromised. The lack of nonce checks, combined with the limited capability checks (only one identified), could also be problematic if any entry points are discovered in the future, though the current analysis reports zero unprotected entry points.

While the plugin has a clean vulnerability history, this should not be interpreted as an absolute guarantee of future safety. The lack of taint analysis data is a significant gap in understanding potential data flow vulnerabilities. The plugin's strengths lie in its minimal attack surface and robust SQL handling. The primary weaknesses are the insufficient output escaping and the potential for XSS if unescaped output is ever exposed to user-controlled data. The reliance on external HTTP requests also introduces a minor, but present, risk. Overall, the plugin is in a decent state, but the output escaping needs immediate attention to mitigate XSS risks.

Key Concerns

  • Low percentage of properly escaped output
  • External HTTP requests present
  • Lack of nonce checks
  • Limited capability checks
Vulnerabilities
None known

ProGrids Widget Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ProGrids Widget Plugin Release Timeline

v3.0.1Current
v3.0.0
v2.0.1
v2.0.0
v1.5.8
v1.5.7
v1.5.6
v1.5.5
v1.5.4
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

ProGrids Widget Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

20% escaped10 total outputs
Attack Surface

ProGrids Widget Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuclasses\ProGrids.php:23
actionadmin_initclasses\ProGrids.php:24
filterthe_contentclasses\ProGrids.php:27
filterpre_update_option_progrids_codeclasses\ProGrids.php:29
actionupdate_option_progrids_codeclasses\ProGrids.php:30
Maintenance & Trust

ProGrids Widget Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.0
Last updatedSep 3, 2014
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

ProGrids Widget Plugin Developer Profile

sazze

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ProGrids Widget Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/progrids-widgets/images/proGridsFav.png/wp-content/plugins/progrids-widgets/css/admin.css
Version Parameters
progrids-widgets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
progrids_container
Data Attributes
data-progrids-widget
JS Globals
proGridsConfig
Shortcode Output
[progrids_widget]
FAQ

Frequently Asked Questions about ProGrids Widget Plugin