
Safe PHP Code Widget Security & Risk Analysis
wordpress.org/plugins/safe-php-code-widgetAdds a secure and simple widget in which you can use PHP and JavaScript code. Also you can use unfiltered HTML or just Text. Admin Use Only.
Is Safe PHP Code Widget Safe to Use in 2026?
Generally Safe
Score 85/100Safe PHP Code Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'safe-php-code-widget' plugin, version 1.0, exhibits a mixed security posture. On the positive side, it demonstrates a strong adherence to secure coding practices by avoiding common vulnerabilities like SQL injection and external HTTP requests, and by utilizing prepared statements for all its SQL queries. The absence of known CVEs and a clean vulnerability history further suggest a currently well-maintained or low-risk profile.
However, the static analysis reveals a critical concern: the presence of the `create_function` dangerous function. This function is known to be a significant security risk as it can lead to arbitrary code execution if used with unsanitized input, effectively bypassing many security controls. Although the taint analysis shows zero flows with unsanitized paths, this does not negate the inherent risk of `create_function` itself. Additionally, the extremely low percentage of properly escaped output (14%) indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, particularly if any user-provided data indirectly reaches an output sink without proper sanitization.
In conclusion, while the plugin's overall architecture appears to have a limited attack surface and no publicly known vulnerabilities, the use of `create_function` and the significant lack of output escaping are substantial weaknesses. These issues introduce potential for critical vulnerabilities, especially if the widget is ever exposed to user-controlled input that is not rigorously validated before being passed to `create_function` or rendered in the output.
Key Concerns
- Use of dangerous function create_function
- Low percentage of properly escaped output
- No nonce checks detected
Safe PHP Code Widget Security Vulnerabilities
Safe PHP Code Widget Release Timeline
Safe PHP Code Widget Code Analysis
Dangerous Functions Found
Output Escaping
Safe PHP Code Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Safe PHP Code Widget Maintenance & Trust
Maintenance Signals
Community Trust
Safe PHP Code Widget Alternatives
Code Widget
code-widget
Code widget help to add Short Code, PHP Code, HTML, and Simple Text in widget.
Insert ShortCode Pattern
insert-shortcode-pattern
Шаблонный текст вставляемый на страницу при помощи шорткода. HTML теги, PHP код
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
CSS & JavaScript Toolbox
css-javascript-toolbox
Add CSS, JavaScript, PHP and HTML code snippets to your site. For AI-powered snippets, get our free plugin here: wpsnippets.ai
Code Embed
simple-embed-code
Code Embed provides a very easy and efficient way to embed code (JavaScript, CSS and HTML) in your posts and pages.
Safe PHP Code Widget Developer Profile
1 plugin · 70 total installs
How We Detect Safe PHP Code Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/safe-php-code-widget/style.css/wp-content/plugins/safe-php-code-widget/execphp.js/wp-content/plugins/safe-php-code-widget/execphp.jssafe-php-code-widget/style.css?ver=safe-php-code-widget/execphp.js?ver=HTML / DOM Fingerprints
widget_execphpexecphpwidgetid="safephpcode-title-name="safephpcode-title-id="safephpcode-text-name="safephpcode-text-id="safephpcode-filter-name="safephpcode-filter-