Smart Archives Reloaded Security & Risk Analysis

wordpress.org/plugins/smart-archives-reloaded

Easily display posts grouped by year and month, in one or more elegant formats

1K active installs v2.0.5 PHP + WP 3.2+ Updated Nov 28, 2017
archivearchivespost-list
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smart Archives Reloaded Safe to Use in 2026?

Generally Safe

Score 85/100

Smart Archives Reloaded has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "smart-archives-reloaded" v2.0.5 plugin exhibits a mixed security posture. On the positive side, there are no known CVEs, the attack surface is minimal with only one shortcode and no unprotected entry points, and there are no external HTTP requests or bundled libraries. This suggests a generally well-maintained and secure codebase in terms of common plugin vulnerabilities and external dependencies.

However, the static analysis reveals significant concerns. A critical taint flow with unsanitized paths is a serious security risk, potentially leading to arbitrary file read or write vulnerabilities if exploited. Furthermore, all SQL queries are executed without prepared statements, which is a high risk for SQL injection vulnerabilities, especially when combined with user-supplied input. The low percentage of properly escaped output (20%) also indicates a potential for Cross-Site Scripting (XSS) vulnerabilities.

While the plugin has no recorded vulnerability history, the current code analysis raises flags that warrant attention. The absence of known CVEs could be due to a lack of public scrutiny or simply a fortunate history. The critical taint flow and the raw SQL queries are direct evidence of potential security weaknesses that need immediate remediation. The plugin's strengths lie in its limited attack surface and lack of external dependencies, but these are overshadowed by the critical taint flow and lack of SQL statement preparation.

Key Concerns

  • Critical taint flow with unsanitized paths
  • SQL queries not using prepared statements
  • Low percentage of output escaping
  • No capability checks
Vulnerabilities
None known

Smart Archives Reloaded Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Smart Archives Reloaded Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
0 prepared
Unescaped Output
20
5 escaped
Nonce Checks
2
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared4 total queries

Output Escaping

20% escaped25 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<Forms> (scb\Forms.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Smart Archives Reloaded Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[smart_archives] core.php:42
WordPress Hooks 12
actionwp_footercore.php:44
filterposts_clausesgenerator.php:340
action_admin_menuscb\AdminPage.php:49
actionadmin_initscb\AdminPage.php:91
actionadmin_noticesscb\AdminPage.php:93
actionadmin_menuscb\AdminPage.php:96
filtercontextual_helpscb\AdminPage.php:97
actionadmin_footerscb\AdminPage.php:322
filtercron_schedulesscb\Cron.php:57
actionactivate_pluginscb\load.php:32
actionplugins_loadedscb\load.php:36
actionwidgets_initscb\Widget.php:13
Maintenance & Trust

Smart Archives Reloaded Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedNov 28, 2017
PHP min version
Downloads99K

Community Trust

Rating86/100
Number of ratings15
Active installs1K
Developer Profile

Smart Archives Reloaded Developer Profile

scribu

20 plugins · 28K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
4851 days
View full developer profile
Detection Fingerprints

How We Detect Smart Archives Reloaded

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smart-archives-reloaded/admin/admin.js/wp-content/plugins/smart-archives-reloaded/admin/admin.dev.js
Script Paths
/wp-content/plugins/smart-archives-reloaded/admin/admin.js/wp-content/plugins/smart-archives-reloaded/admin/admin.dev.js
Version Parameters
smart-archives-reloaded/admin/admin.js?ver=1.9smart-archives-reloaded/admin/admin.dev.js?ver=1.9

HTML / DOM Fingerprints

Data Attributes
SAR_Settings
FAQ

Frequently Asked Questions about Smart Archives Reloaded