
scifi Facets Security & Risk Analysis
wordpress.org/plugins/scifi-facetsscifi Facets is simple facet widget which allow adding a widget
Is scifi Facets Safe to Use in 2026?
Generally Safe
Score 85/100scifi Facets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The scifi-facets plugin v0.6.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and avoiding file operations and external HTTP requests. The absence of known CVEs and a clean vulnerability history further suggests a relatively stable development. However, significant concerns arise from the static code analysis. The presence of the `create_function` dangerous function is a notable risk, as it can be exploited for code injection if user input is not rigorously sanitized before being passed to it. Furthermore, the plugin's output escaping is alarmingly low at only 23%, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks on potential entry points, while currently having a small attack surface, leaves it vulnerable to future expansion or exploitation if new entry points are introduced without proper security measures. The taint analysis shows no current issues, but this may be due to the limited complexity or specific nature of the plugin's code, and does not negate the risks identified by other signals.
Key Concerns
- Dangerous function used (create_function)
- Low output escaping percentage
- No nonce checks on entry points
- No capability checks on entry points
scifi Facets Security Vulnerabilities
scifi Facets Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
scifi Facets Attack Surface
WordPress Hooks 4
Maintenance & Trust
scifi Facets Maintenance & Trust
Maintenance Signals
Community Trust
scifi Facets Alternatives
Category Order and Taxonomy Terms Order
taxonomy-terms-order
Drag-and-drop ordering for Categories & any taxonomy (hierarchically) using a Drag and Drop Sortable JavaScript capability.
Beautiful taxonomy filters
beautiful-taxonomy-filters
Supercharge your custom post type archives by letting visitors filter posts by their terms/categories. This plugin handles the whole thing for you!
Post Terms Order – per Post based
post-terms-order
Sort Taxonomy Terms per Post basis using a Drag and Drop Sortable JavaScript capability.
I Order Terms
i-order-terms
Allows theme developers to add order/sort functionality for categories, tags and custom taxonomies.
JSM Show Term Metadata
jsm-show-term-meta
Show term metadata in a metabox when editing terms - a great tool for debugging issues with term metadata.
scifi Facets Developer Profile
5 plugins · 200 total installs
How We Detect scifi Facets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scifi-facets/scifi-facets.css/wp-content/plugins/scifi-facets/scifi-facets.js/wp-content/plugins/scifi-facets/scifi-facets.jsscifi-facets.css?ver=scifi-facets.js?ver=HTML / DOM Fingerprints
scifi-facets-widgetscifi-facets-orderingscifi-facets-orderby-selectorscifi-facets-order-selectorscifi-facets-order-selector-ascscifi-facets-order-selector-descdata-taxonomydata-fielddata-titledata-urlbasedata-urlbase_customdata-showempty+9 morescifiFacets<div class="scifi-facets-ordering"><select id="scifi-facets-orderby-selectoronchange="window.location.href=this.value"