
Flynsarmy Subcategory List Widget Security & Risk Analysis
wordpress.org/plugins/subcategory-list-widgetAdds a widget that can displays subcategories of a given category (or top level).
Is Flynsarmy Subcategory List Widget Safe to Use in 2026?
Generally Safe
Score 85/100Flynsarmy Subcategory List Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "subcategory-list-widget" v1.2.2 plugin exhibits a generally good security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a limited attack surface. Furthermore, the code's commitment to using prepared statements for all SQL queries is commendable and mitigates common SQL injection risks. The lack of file operations and external HTTP requests also reduces potential attack vectors.
However, a significant concern arises from the output escaping analysis, where only 14% of outputs are properly escaped. This low percentage suggests a high likelihood of cross-site scripting (XSS) vulnerabilities. If user-supplied or dynamic data is displayed without adequate sanitization, attackers could inject malicious scripts into the website. The absence of nonce checks and capability checks, especially in conjunction with the low output escaping rate, further exacerbates this risk, as there are no built-in mechanisms to verify user intent or permissions for actions that might involve rendering dynamic content.
The plugin's vulnerability history is also a positive indicator, with no known CVEs recorded. This, combined with the static analysis showing no critical or high-severity taint flows, suggests that the core functionality may be relatively secure. However, the lack of past vulnerabilities should not be mistaken for an absence of risk, particularly given the identified output escaping issues. The balanced conclusion is that while the plugin has a small attack surface and good SQL practices, the widespread lack of output escaping presents a substantial XSS risk that needs immediate attention.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Flynsarmy Subcategory List Widget Security Vulnerabilities
Flynsarmy Subcategory List Widget Code Analysis
Output Escaping
Flynsarmy Subcategory List Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Flynsarmy Subcategory List Widget Maintenance & Trust
Maintenance Signals
Community Trust
Flynsarmy Subcategory List Widget Alternatives
Category and Subcategory List Widget
category-subcategory-list-widget
This widget allows to add/update icons for category or icon for custom taxonomy. It lists Categories in horizontal menu pattern.
Iks Menu – WordPress Category Accordion Menu & FAQs
iks-menu
Super customizable WordPress plugin for displaying custom menus, taxonomy/category terms and FAQs as accordion menu (with images support).
NS Category Widget
ns-category-widget
A plugin to add widget for listing Categories and Taxonomies. Extending Default WordPress Category Widget.
Most Popular Categories
most-popular-categories
Display your most popular categories in a widget
Product List / Grid View for Woocommerce
gm-woo-product-list-widget
WooCommerce Products List / Grid View allows you to display a Fileter selection of products. woocommerce Product display shortcode uses the same styli …
Flynsarmy Subcategory List Widget Developer Profile
2 plugins · 80 total installs
How We Detect Flynsarmy Subcategory List Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subcategory-list-widget/views/subcat-widget/frontend/widget.phpHTML / DOM Fingerprints
flyn-subcat-list-widget