
Subzane Categorized Archive Widget Security & Risk Analysis
wordpress.org/plugins/subzane-categorized-archive-widgetA widget that displays an archive for the current selected category. On non-category pages a standard archive is displayed.
Is Subzane Categorized Archive Widget Safe to Use in 2026?
Generally Safe
Score 85/100Subzane Categorized Archive Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "subzane-categorized-archive-widget" plugin v1.0 appears to be mixed. On one hand, the static analysis indicates a lack of common attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited without proper authentication. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and a complete lack of taint flows with unsanitized paths are positive signs. The SQL queries are also all prepared, which is a good practice.
However, a significant concern is the complete lack of output escaping for all identified output points. This means that any data displayed by the widget could potentially be vulnerable to cross-site scripting (XSS) attacks if the input is not properly sanitized before being output. The absence of nonce and capability checks on any potential entry points (though none were found) is also a general weakness. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past security diligence, but this does not mitigate the identified risks in the current codebase.
In conclusion, while the plugin has a small attack surface and good practices regarding SQL and avoiding dangerous functions, the pervasive lack of output escaping presents a critical security weakness. The absence of nonce and capability checks, while not directly exploitable based on the current attack surface, indicates a potential for future vulnerabilities if new entry points are added without these security measures. The clean vulnerability history is commendable but should not overshadow the immediate risks identified in the code.
Key Concerns
- 0% output escaping
- 0 capability checks
- 0 nonce checks
Subzane Categorized Archive Widget Security Vulnerabilities
Subzane Categorized Archive Widget Code Analysis
Output Escaping
Subzane Categorized Archive Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Subzane Categorized Archive Widget Maintenance & Trust
Maintenance Signals
Community Trust
Subzane Categorized Archive Widget Alternatives
Recent Archive More Widget
recent-archive-more-widget
'Recent Archive More Widget' displays posts, not listed on page content area on the widget area of the sidebar of category archive page.
Elementor Custom Skin
ele-custom-skin
Create new skins for Elementor PRO 3.x page builder. Design your own skins for Post and Post Archive Widgets using Elementor Loop Templates.
Add Category to Pages
add-category-to-pages
Easily add a Post Categories to Wordpress Pages
Create And Assign Categories For Pages
create-and-assign-categories-for-pages
Easily create/add post Categories to your Wordpress Pages
Iks Menu – WordPress Category Accordion Menu & FAQs
iks-menu
Super customizable WordPress plugin for displaying custom menus, taxonomy/category terms and FAQs as accordion menu (with images support).
Subzane Categorized Archive Widget Developer Profile
3 plugins · 110 total installs
How We Detect Subzane Categorized Archive Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
subzane_categorized_archive_titlesubzane_categorized_archive_showemptysubzane_categorized_archive_showcountsubzane_categorized_archive_submit