
Site-settings Security & Risk Analysis
wordpress.org/plugins/sites-settingsSite-settings is the ultimate plugin for making all the necessary changes in the custom fields of a website.
Is Site-settings Safe to Use in 2026?
Generally Safe
Score 100/100Site-settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'sites-settings' plugin version 1.1.0 demonstrates a generally strong security posture, with no known vulnerabilities in its history and a positive code analysis. The absence of CVEs suggests a commitment to secure coding practices. The static analysis reveals a minimal attack surface, consisting of a single shortcode, with no unprotected entry points identified. Furthermore, the plugin effectively utilizes prepared statements for all SQL queries and exhibits a high percentage of properly escaped output, mitigating risks of SQL injection and cross-site scripting (XSS). The presence of a nonce check and the use of a bundled library like Select2 (though its version is not specified) are also good practices.
However, there are a couple of areas that warrant attention. The taint analysis shows two flows with unsanitized paths, which, although not classified as critical or high severity in this analysis, represent a potential avenue for malicious input to be processed without proper validation. Additionally, the plugin lacks capability checks on its entry points, meaning that potentially sensitive operations could be performed by users without the necessary permissions. While the current absence of documented vulnerabilities is a positive sign, the presence of unsanitized paths and missing capability checks represent potential weaknesses that could be exploited if an attacker discovers them, especially as the plugin evolves or is integrated into more complex environments.
Key Concerns
- Unsanitized paths in taint analysis
- Missing capability checks
Site-settings Security Vulnerabilities
Site-settings Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Site-settings Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Site-settings Maintenance & Trust
Maintenance Signals
Community Trust
Site-settings Alternatives
Import / Export Customizer Settings
astra-import-export
Astra theme customizer offers several settings for header/footer layout, sidebar and blog designs, colors, backgrounds, typography and much more.
WP Settings:WordPress Settings and Database Backup
wp-settings
Display useful information about WordPress,plugins,database and generate database backup script.Configure WordPress by analyzing common settings...
Customizer Toolkits
customizer-toolkits
Customizer Toolkits is a nice wordpress plugin. You can use this plugin any wordpress site for create Customizer Options. Customizer Toolkits is one o …
PuppyFW
puppyfw
PuppyFW is a lightweight but powerful options framework for WordPress themes and plugins which supports tab, group, repeatable, field dependencies.
Site-settings Developer Profile
6 plugins · 3K total installs
How We Detect Site-settings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sites-settings/assets/css/bootstrap.min.css/wp-content/plugins/sites-settings/assets/css/select2.css/wp-content/plugins/sites-settings/assets/css/style.css/wp-content/plugins/sites-settings/assets/js/select2.js/wp-content/plugins/sites-settings/assets/js/ctss.js/wp-content/plugins/sites-settings/assets/js/select2.js/wp-content/plugins/sites-settings/assets/js/ctss.jssites-settings/assets/css/style.css?ver=sites-settings/assets/js/ctss.js?ver=HTML / DOM Fingerprints
success_msgdata-select2-idwp.mediatb_show[ss_option][ss_option]site_tags[/ss_option][ss_option]product_tags[/ss_option][ss_option]site_logo[/ss_option]