
Simple Page Hierarchy Widget Security & Risk Analysis
wordpress.org/plugins/simple-page-hierarchy-widgetDisplays the most logical arrangement of Parent, Child, & Grandchild pages.
Is Simple Page Hierarchy Widget Safe to Use in 2026?
Generally Safe
Score 85/100Simple Page Hierarchy Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The `simple-page-hierarchy-widget` plugin, in version 1.0.3, exhibits a generally positive security posture concerning its attack surface and SQL query handling. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's potential exposure points. Furthermore, all detected SQL queries utilize prepared statements, which is an excellent security practice. However, the plugin's security is notably compromised by the presence of a dangerous function (`create_function`) and a complete lack of output escaping. This means that any data processed or displayed by the plugin, especially if it originates from user input or external sources, could be vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks further exacerbates this risk by not providing basic authentication and authorization mechanisms for potentially sensitive operations, even if the attack surface is currently limited. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strength. However, this clean history, combined with the identified code-level weaknesses, could suggest that the plugin hasn't been thoroughly audited for certain vulnerability types or that the observed issues haven't yet been exploited in the wild. The overall assessment is that while the plugin avoids common entry point vulnerabilities, the identified code signals present significant and exploitable risks, particularly concerning XSS.
Key Concerns
- Dangerous function found (create_function)
- Output escaping is not implemented
- No nonce checks
- No capability checks
Simple Page Hierarchy Widget Security Vulnerabilities
Simple Page Hierarchy Widget Code Analysis
Dangerous Functions Found
Output Escaping
Simple Page Hierarchy Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Simple Page Hierarchy Widget Maintenance & Trust
Maintenance Signals
Community Trust
Simple Page Hierarchy Widget Alternatives
Protect the Children!
protect-the-children
Easily password protect the child pages/posts of a post/page that is password protected.
Widgets on Pages
widgets-on-pages
The easiest and highest rated way to Add Widgets or Sidebars to Posts and Pages using Visual editor, shortcodes or template tags.
CC Child Pages
cc-child-pages
Display WordPress child pages in a responsive grid or list using a shortcode, Gutenberg block or Elementor widget.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
List Pages Shortcode
list-pages-shortcode
Introduces the [list-pages], [sibling-pages] and [child-pages] shortcodes for easily displaying a list of pages within a post or page.
Simple Page Hierarchy Widget Developer Profile
2 plugins · 120 total installs
How We Detect Simple Page Hierarchy Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-page-hierarchy-widget/style.css/wp-content/plugins/simple-page-hierarchy-widget/js/widget.js/wp-content/plugins/simple-page-hierarchy-widget/js/widget.jssimple-page-hierarchy-widget/style.css?ver=simple-page-hierarchy-widget/js/widget.js?ver=HTML / DOM Fingerprints
gb-page-hierarchy-widget