static template page Security & Risk Analysis

wordpress.org/plugins/static-template-page

Create Static Pages

10 active installs v1.0 PHP + WP 3.0+ Updated Jul 7, 2011
cms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is static template page Safe to Use in 2026?

Generally Safe

Score 85/100

static template page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The static analysis of "static-template-page" v1.0 reveals a generally positive security posture, with no identified critical vulnerabilities in the provided data. The plugin exhibits excellent practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no external HTTP requests or file operations. The absence of known CVEs and a history of vulnerabilities further strengthens its perceived security. However, a significant concern lies in the lack of capability checks (0 recorded) for its entry points. While the attack surface is currently reported as zero, this absence of explicit permission checks means that if any entry points were to be introduced or discovered in the future, they would be unprotected by default, posing a potential risk. Additionally, only 25% of output is properly escaped, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs handle user-supplied data without further sanitization. The presence of a nonce check is a positive, but the lack of capability checks for entry points is a notable weakness that could become a significant issue if the attack surface grows.

Key Concerns

  • Low output escaping percentage
  • No capability checks on entry points
Vulnerabilities
None known

static template page Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

static template page Release Timeline

v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v0.2
v0.1
Code Analysis
Analyzed Mar 17, 2026

static template page Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Attack Surface

static template page Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actiondeleted_postkaluto-static-template-page.php:77
actioninitkaluto-static-template-page.php:78
actionadmin_noticeskaluto-static-template-page.php:79
actioninitkaluto-static-template-page.php:80
filtertemplate_includekaluto-static-template-page.php:81
Maintenance & Trust

static template page Maintenance & Trust

Maintenance Signals

WordPress version tested3.1.4
Last updatedJul 7, 2011
PHP min version
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

static template page Developer Profile

Koff

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect static template page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/static-template-page/api.php

HTML / DOM Fingerprints

Shortcode Output
This page is place order for $name.
FAQ

Frequently Asked Questions about static template page