Simply Excerpts Security & Risk Analysis

wordpress.org/plugins/simply-excerpts

A simple plugin for exceprts that allows you to change the word count and to replace the elipsis (...) with text. Not compatible with all themes.

500 active installs v1.7 PHP + WP + Updated Feb 22, 2026
excerptsread-moreword-count
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 13, 2023
Safety Verdict

Is Simply Excerpts Safe to Use in 2026?

Generally Safe

Score 100/100

Simply Excerpts has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 13, 2023Updated 1mo ago
Risk Assessment

The 'simply-excerpts' plugin version 1.7 presents a mixed security picture. On the positive side, the static analysis reveals a remarkably small attack surface with no identified entry points that lack authorization checks. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are common vectors for vulnerabilities. However, the output escaping is not entirely robust, with 18% of outputs not being properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully in those instances.

The plugin's vulnerability history shows one past medium-severity CVE related to XSS, which was last observed on November 13, 2023. While this specific vulnerability is marked as patched, the pattern of XSS suggests that careful input sanitization and output escaping remain crucial areas for this plugin. The lack of any observed taint flows or dangerous functions in the current static analysis is a positive sign, but the past vulnerability and the incomplete output escaping warrant attention. Overall, while the current version appears to have addressed past issues and maintains good practices in many areas, the potential for unescaped output and the historical XSS vulnerability suggest that ongoing vigilance is necessary.

Key Concerns

  • Some outputs not properly escaped
  • One past medium CVE (XSS)
Vulnerabilities
1

Simply Excerpts Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-5137medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simply Excerpts <= 1.4 - Authenticated (Admin+) Stored Cross-Site Scripting

Nov 13, 2023 Patched in 1.6 (71d)
Code Analysis
Analyzed Mar 16, 2026

Simply Excerpts Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped11 total outputs
Attack Surface

Simply Excerpts Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menusimply-excerpts.php:44
actionadmin_initsimply-excerpts.php:45
filterexcerpt_moresimply-excerpts.php:168
filterthe_excerptsimply-excerpts.php:216
filterexcerpt_lengthsimply-excerpts.php:219
Maintenance & Trust

Simply Excerpts Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 22, 2026
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings2
Active installs500
Developer Profile

Simply Excerpts Developer Profile

A. Jones

5 plugins · 4K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
121 days
View full developer profile
Detection Fingerprints

How We Detect Simply Excerpts

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
more-link
FAQ

Frequently Asked Questions about Simply Excerpts