
Simple Archive Generator Security & Risk Analysis
wordpress.org/plugins/simple-archive-generatorA very simple (to use and configure) plug-in to generate a complete list (by category) of all posts.
Is Simple Archive Generator Safe to Use in 2026?
High Risk
Score 41/100Simple Archive Generator carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The "simple-archive-generator" v5.2 plugin presents a mixed security posture. On one hand, the static analysis indicates a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The absence of dangerous functions and file operations is also positive. Furthermore, all SQL queries are reportedly using prepared statements, which is a strong security practice.
However, significant concerns arise from the output escaping and vulnerability history. The static analysis shows that 0% of the 21 identified output points are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while limited, found two flows with unsanitized paths, which could be exploited if they lead to output functions that are not properly escaped. The plugin also has a history of two known medium-severity CVEs, both of which are currently unpatched and related to XSS and Cross-Site Request Forgery (CSRF). The presence of unpatched vulnerabilities, especially when combined with a lack of output escaping, significantly elevates the risk profile.
In conclusion, while the plugin has a limited attack surface and uses prepared statements for SQL, the complete lack of output escaping and the existence of unpatched XSS/CSRF vulnerabilities create a substantial security risk. The developers need to urgently address the output escaping issues and patch the known CVEs to improve the plugin's security. The current state makes it susceptible to common web attacks, potentially impacting user data and site integrity.
Key Concerns
- Unpatched CVEs (2)
- No output escaping
- Taint flows with unsanitized paths (2)
Simple Archive Generator Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Simple Archive Generator <= 5.2 - Reflected Cross-Site Scripting
Simple Archive Generator <= 5.2 - Cross-Site Request Forgery
Simple Archive Generator Release Timeline
Simple Archive Generator Code Analysis
Output Escaping
Data Flow Analysis
Simple Archive Generator Attack Surface
WordPress Hooks 6
Maintenance & Trust
Simple Archive Generator Maintenance & Trust
Maintenance Signals
Community Trust
Simple Archive Generator Alternatives
Elementor Custom Skin
ele-custom-skin
Create new skins for Elementor PRO 3.x page builder. Design your own skins for Post and Post Archive Widgets using Elementor Loop Templates.
Simple CSS
simple-css
Add CSS to your website through an admin editor, the Customizer or a metabox for page/post specific CSS.
Add Category to Pages
add-category-to-pages
Easily add a Post Categories to Wordpress Pages
Catch IDs
catch-ids
What this plugin does is to shows the IDs on admin section.
Simple Taxonomy Ordering
simple-taxonomy-ordering
Quickly and easily reorder taxonomy terms with an easy to use and intuitive drag and drop interface.
Simple Archive Generator Developer Profile
5 plugins · 230 total installs
How We Detect Simple Archive Generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-archive-generator/icon_minus.gif/wp-content/plugins/simple-archive-generator/icon_plus.gifHTML / DOM Fingerprints
simple_acatsimple_aheadingsimple_alinkid="cat-control-id="cat-list-class="no-rate"sa_show_hide(