SimplePage – Sync Landing Page For Web Security & Risk Analysis

wordpress.org/plugins/simplepage-sync-landing-page-for-web

Đồng bộ các dự án Landing Page đã thiết kế tại nền tảng tạo Landing Page miễn phí SimplePage.vn lên Website Wordpress của bạn.

30 active installs v1.2.0 PHP + WP 4.6+ Updated Nov 11, 2021
landing-pagelandingpage
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SimplePage – Sync Landing Page For Web Safe to Use in 2026?

Generally Safe

Score 85/100

SimplePage – Sync Landing Page For Web has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The overall security posture of the "simplepage-sync-landing-page-for-web" plugin v1.2.0 appears to be relatively strong, with no known critical vulnerabilities in its history and no identified issues in taint analysis. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing a nonce check on its single AJAX handler. Furthermore, there are no external HTTP requests, which can often be a source of vulnerabilities. However, there are areas for improvement that introduce potential risks.

The static analysis reveals a significant concern regarding output escaping. With only 13% of outputs properly escaped across 16 instances, there is a high risk of cross-site scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-controlled input that is not sufficiently sanitized before being displayed on the page. While the attack surface is small and the single AJAX handler has a nonce check, the lack of robust output escaping represents a notable weakness.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive indicator of its current security state. However, the lack of vulnerability history doesn't guarantee future safety, especially given the identified output escaping issues. The plugin's strengths lie in its secure database interactions and limited attack surface. The primary weakness is the insufficient handling of output, which could be exploited if user input is not properly validated and escaped.

Key Concerns

  • Low percentage of properly escaped outputs
  • No capability checks on entry points
Vulnerabilities
None known

SimplePage – Sync Landing Page For Web Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SimplePage – Sync Landing Page For Web Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

13% escaped16 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
getListLandingPage (simplepage-sync-landing-page-for-web.php:258)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SimplePage – Sync Landing Page For Web Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_getListLandingPagesimplepage-sync-landing-page-for-web.php:30
WordPress Hooks 7
actionadmin_enqueue_scriptssimplepage-sync-landing-page-for-web.php:26
actionadmin_menusimplepage-sync-landing-page-for-web.php:28
actionadmin_initsimplepage-sync-landing-page-for-web.php:29
filterpage_attributes_dropdown_pages_argssimplepage-sync-landing-page-for-web.php:35
filtertheme_page_templatessimplepage-sync-landing-page-for-web.php:37
filterwp_insert_post_datasimplepage-sync-landing-page-for-web.php:40
filtertemplate_includesimplepage-sync-landing-page-for-web.php:41
Maintenance & Trust

SimplePage – Sync Landing Page For Web Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedNov 11, 2021
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

SimplePage – Sync Landing Page For Web Developer Profile

Truong Thanh

2 plugins · 830 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SimplePage – Sync Landing Page For Web

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simplepage-sync-landing-page-for-web/admin/css/style.css/wp-content/plugins/simplepage-sync-landing-page-for-web/admin/js/script.js
Script Paths
/wp-content/plugins/simplepage-sync-landing-page-for-web/admin/js/script.js
Version Parameters
simplepage-sync-landing-page-for-web/admin/css/style.css?ver=simplepage-sync-landing-page-for-web/admin/js/script.js?ver=

HTML / DOM Fingerprints

JS Globals
simplepageGetLDP
REST Endpoints
/wp-json/simplepage/v1/landing-pages
FAQ

Frequently Asked Questions about SimplePage – Sync Landing Page For Web