
Simple Forum Widgets Security & Risk Analysis
wordpress.org/plugins/simple-forum-widgetsAdds two new widgets (Forum Threads and Forum Categories) to display your Simple Forum Threads/Categories on your site
Is Simple Forum Widgets Safe to Use in 2026?
Generally Safe
Score 85/100Simple Forum Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'simple-forum-widgets' plugin version 1.0.3 exhibits a mixed security posture. On the positive side, there are no known CVEs, no complex attack surface with AJAX handlers, REST API routes, or shortcodes, and all SQL queries utilize prepared statements. File operations are absent, and there are no bundled libraries to worry about. This suggests a generally well-structured codebase with some good security practices. However, significant concerns arise from the static analysis. The presence of two instances of the deprecated and inherently insecure `create_function` is a major red flag, as it can be a vector for code injection if user input is involved. Furthermore, only 14% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealing four flows with unsanitized paths, even without a critical or high severity classification, points to potential data leakage or manipulation risks that need thorough investigation. The absence of nonce checks on any potential entry points (though the attack surface is currently zero) and a single capability check, while not directly indicative of current vulnerabilities, represent areas where robust access control might be lacking if the plugin were to evolve. The lack of vulnerability history is reassuring, but the current code quality issues present inherent risks that cannot be ignored.
Key Concerns
- Use of create_function (2 instances)
- Low output escaping percentage (14%)
- Taint flows with unsanitized paths (4 flows)
- No nonce checks detected
Simple Forum Widgets Security Vulnerabilities
Simple Forum Widgets Release Timeline
Simple Forum Widgets Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Simple Forum Widgets Attack Surface
WordPress Hooks 9
Maintenance & Trust
Simple Forum Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Simple Forum Widgets Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Simple Forum Widgets Developer Profile
1 plugin · 10 total installs
How We Detect Simple Forum Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-forum-widgets/assets/css/simple-forum-widgets.css/wp-content/plugins/simple-forum-widgets/assets/js/simple-forum-widgets.jssimple-forum-widgets/assets/css/simple-forum-widgets.css?ver=simple-forum-widgets/assets/js/simple-forum-widgets.js?ver=HTML / DOM Fingerprints
sf-secretdata-lengthjQuery/SFRequest=generate-secret