
Squeeze Page Toolkit for WordPress Security & Risk Analysis
wordpress.org/plugins/squeeze-page-toolkitThe official Squeeze Page Toolkit plugin that connects your account for hosting your squeeze pages and landing pages on your WordPress website.
Is Squeeze Page Toolkit for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Squeeze Page Toolkit for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'squeeze-page-toolkit' plugin v1.20 presents a mixed security posture. While the static analysis indicates a commendable lack of direct attack surface through AJAX, REST API, shortcodes, or cron events, and crucially, no recorded vulnerabilities or CVEs, significant concerns arise from the code analysis. The presence of dangerous functions like `create_function` and `unserialize`, coupled with a very low rate of properly escaped output (only 6%), indicates a high risk of potential cross-site scripting (XSS) or remote code execution (RCE) vulnerabilities, especially if any of the input streams were to become exposed or manipulated.
The taint analysis revealing two flows with unsanitized paths, even without critical or high severity, suggests potential pathways for malicious data to be processed without adequate validation or sanitization. The complete absence of nonce and capability checks on any entry points, combined with the use of `unserialize`, makes it highly probable that attackers could inject malicious code or alter plugin behavior by crafting specific inputs. This is further exacerbated by the fact that 50% of SQL queries are not using prepared statements, increasing the risk of SQL injection.
Despite a clean vulnerability history, which is a positive sign, the identified code signals and taint flows represent significant inherent risks. The plugin needs substantial security improvements in data handling, output sanitization, and the implementation of authentication and authorization checks to mitigate these potential vulnerabilities. The lack of historical issues should not breed complacency given the evident weaknesses in the current code.
Key Concerns
- Dangerous function: unserialize
- Dangerous function: create_function
- Unsanitized paths in taint analysis
- Low output escaping rate (6%)
- No nonce checks
- No capability checks
- SQL queries not using prepared statements (50%)
Squeeze Page Toolkit for WordPress Security Vulnerabilities
Squeeze Page Toolkit for WordPress Release Timeline
Squeeze Page Toolkit for WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Squeeze Page Toolkit for WordPress Attack Surface
WordPress Hooks 14
Maintenance & Trust
Squeeze Page Toolkit for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Squeeze Page Toolkit for WordPress Alternatives
Bulk Page Generator and Mass Page Builder – Page Generator
page-generator
Bulk generate multiple Pages using dynamic content.
Woorise – Landing Pages, Forms & Surveys
woorise
Create landing pages, forms, surveys, quizzes and viral giveaways.
ONTRApages
ontrapages
ONTRApages for WordPress allows Ontraport Premium users to connect to their accounts and easily publish their landing pages on their own WordPress sit …
Landing Page Cat – Coming Soon & Maintenance Pages
landing-page-cat
Landing Page Cat Lets You Publish A Beautiful Coming Soon Page, Maintenance Page or Squeeze Page For WordPress, In Just 2 Minutes.
UTMs Carry Pages
utms-carry-pages
Simplest way to pass UTM between pages.
Squeeze Page Toolkit for WordPress Developer Profile
1 plugin · 20 total installs
How We Detect Squeeze Page Toolkit for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/squeeze-page-toolkit/wplib/utils_settings.inc.php/wp-content/plugins/squeeze-page-toolkit/wplib/utils_pagebuilder.inc.php/wp-content/plugins/squeeze-page-toolkit/lib/common.inc.php/wp-content/plugins/squeeze-page-toolkit/lib/admin_only.inc.php/wp-content/plugins/squeeze-page-toolkit/lib/db.inc.phpHTML / DOM Fingerprints
sptk_for_wp_adminbardata-sptk-page-idsptk_vars/wp-json/sptk/v1/pages/wp-json/sptk/v1/settings[sptk_page id=""]