
Subpage Listing Security & Risk Analysis
wordpress.org/plugins/subpage-listingAllows you to display a list of the child pages of the currently viewed page.
Is Subpage Listing Safe to Use in 2026?
Generally Safe
Score 85/100Subpage Listing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'subpage-listing' plugin v0.6.2 exhibits a concerning security posture due to significant code analysis findings, despite a clean vulnerability history. The absence of any known CVEs is positive, suggesting the plugin hasn't historically been a target or has been developed with a focus on avoiding common vulnerabilities. However, the static analysis reveals critical weaknesses. Notably, the presence of the `create_function` function is a red flag, as it can lead to arbitrary code execution if used with unsanitized input. Furthermore, the analysis indicates that 100% of output is not properly escaped, which poses a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce and capability checks, combined with zero AJAX handlers and REST API routes being analyzed for authorization, means any potential entry points, if discovered, would be unprotected. While the plugin demonstrates good practices by using prepared statements for all SQL queries, this is overshadowed by the unescaped output and the dangerous function usage.
Key Concerns
- Use of dangerous function create_function
- 100% of output unescaped
- No nonce checks found
- No capability checks found
Subpage Listing Security Vulnerabilities
Subpage Listing Code Analysis
Dangerous Functions Found
Output Escaping
Subpage Listing Attack Surface
WordPress Hooks 2
Maintenance & Trust
Subpage Listing Maintenance & Trust
Maintenance Signals
Community Trust
Subpage Listing Alternatives
WenderHost Subpages Widget
wenderhost-subpages-widget
A widget for displaying a list of subpage links. The list remains consistent regardless of where you are in the hierarchy.
Nested Pages
wp-nested-pages
Nested Pages provides a drag and drop interface for managing pages & posts in the WordPress admin, while maintaining quick edit functionality.
CMS Tree Page View
cms-tree-page-view
Adds a tree view of all pages & custom posts. Get a great overview + options to drag & drop to reorder & option to add multiple pages.
Page-list
page-list
[pagelist], [subpages], [siblings] and [pagelist_ext] shortcodes
Admin Menu Tree Page View
admin-menu-tree-page-view
Get a tree view of all your pages directly in the admin menu. Search, add, edit, view, re-order – all is just one click away!
Subpage Listing Developer Profile
29 plugins · 176K total installs
How We Detect Subpage Listing
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subpage-listing/style.css?ver=0.6.2/wp-content/plugins/subpage-listing/script.js?ver=0.6.2HTML / DOM Fingerprints
page_itemtxfx_subpages<!--%subpages%--><!--%subpages(%)%-->id="txfx_subpages"value="Subpage List"txfx_insertAtCursor<ul>
<li class="page_item">↑<a href="</ul></li><li class="page_item">↑<a href="
<li class="page_item">↑<a href="