
Suggestion Toolkit Security & Risk Analysis
wordpress.org/plugins/suggestion-toolkitThis plugin provides a fast and flexible way to add recommendations of a different kinds on WordPress website pages, almost any place on the website.
Is Suggestion Toolkit Safe to Use in 2026?
Use With Caution
Score 63/100Suggestion Toolkit has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The suggestion-toolkit plugin v5.0 exhibits a concerning security posture, primarily due to a significant lack of authorization checks on its entry points. With 7 out of 8 total entry points being unprotected AJAX handlers, this creates a large attack surface vulnerable to unauthorized actions. The static analysis also highlights issues with SQL query security, as none of the queries utilize prepared statements, and only a small percentage of outputs are properly escaped, increasing the risk of data leakage or manipulation. While the plugin has a history of vulnerabilities, including one unpatched medium severity CVE, the static analysis did not directly flag critical or high severity taint flows. However, the pattern of past vulnerabilities, particularly 'Missing Authorization,' strongly correlates with the current findings of unprotected AJAX handlers. The absence of nonce checks and capability checks further exacerbates these risks.
Despite the critical issues identified, the plugin does not appear to bundle outdated libraries and has not flagged any dangerous functions. Nevertheless, the prevalence of unprotected entry points, the lack of proper SQL sanitization, and the historical vulnerability trends paint a picture of a plugin that requires immediate attention to mitigate significant security risks. The focus on securing AJAX handlers and implementing robust authorization mechanisms is paramount.
Key Concerns
- 7 unprotected AJAX handlers
- 0 Nonce checks
- 0 Capability checks
- 2 SQL queries, 0% prepared
- 12% properly escaped output
- 1 unpatched medium CVE
- 3 unsanitized path flows
Suggestion Toolkit Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Suggestion Toolkit <= 5.0 - Missing Authorization
Suggestion Toolkit Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Suggestion Toolkit Attack Surface
AJAX Handlers 7
Shortcodes 1
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
Suggestion Toolkit Maintenance & Trust
Maintenance Signals
Community Trust
Suggestion Toolkit Alternatives
Suggestion Toolkit – Youtube
suggestion-toolkit-youtube
This plugin is an extension for Suggestion Toolkit. It allows to include YouTube video suggestions into suggestion blocks on your WordPress blog or we …
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
Social Semantic Recommendation (SOSERE)
social-semantic-recommendation-sosere
Display a list of related entries on your site based on an unique, self-learning, socialsemantic network analysis algorithm.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Suggestion Toolkit Developer Profile
4 plugins · 200 total installs
How We Detect Suggestion Toolkit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/suggestion-toolkit/assets/css/script.css/wp-content/plugins/suggestion-toolkit/assets/js/script.js/wp-content/plugins/suggestion-toolkit/assets/css/admin.css/wp-content/plugins/suggestion-toolkit/assets/js/admin.js/wp-content/plugins/suggestion-toolkit/assets/js/script.jssuggestion-toolkit/assets/css/script.css?ver=suggestion-toolkit/assets/js/script.js?ver=suggestion-toolkit/assets/css/admin.css?ver=suggestion-toolkit/assets/js/admin.js?ver=HTML / DOM Fingerprints
suggestion-toolkit-widgetsuggestion-toolkit-settings-pagesuggestion-toolkit-admin-menudata-suggestion-toolkit-iddata-suggestion-toolkit-settingssuggestionToolkit/wp-json/suggestion-toolkit/v1/settings[rel_posts]