
Super Widgets Security & Risk Analysis
wordpress.org/plugins/super-widgetsFeature posts in your sidebar. Select posts by Blog (multisite), individually, by Post Type, or by Tag/Category/Taxonomy.
Is Super Widgets Safe to Use in 2026?
Generally Safe
Score 85/100Super Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'super-widgets' v0.1 plugin exhibits a mixed security posture. On one hand, it shows a commendable lack of common entry points like AJAX handlers, REST API routes, shortcodes, and cron events that are not protected by authentication. The absence of file operations and external HTTP requests further reduces potential attack vectors. Furthermore, all identified SQL queries utilize prepared statements, which is a strong defense against SQL injection. However, several concerning signals emerge from the code analysis. The presence of four instances of `create_function` is a significant red flag, as this function is deprecated and can be a source of security vulnerabilities if not used with extreme caution. The most critical concern is the extremely low rate of proper output escaping, with only 11% of outputs being escaped. This indicates a high probability of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the WordPress site. The complete absence of nonce checks and capability checks on any potential entry points (even though the attack surface appears minimal) further exacerbates the risk, as it means even if an entry point were to be discovered, it would lack essential security controls.
The vulnerability history for 'super-widgets' is clean, with no recorded CVEs. While this is positive, it could be attributed to the plugin's early version (0.1) and potentially limited usage or scrutiny. It does not guarantee future security. The combination of dangerous function usage and severe output escaping deficiencies, despite a clean history and minimal apparent attack surface, presents a substantial risk. The plugin's strengths lie in its controlled SQL usage and limited entry points, but these are overshadowed by critical weaknesses in output sanitization and the use of insecure coding practices.
Key Concerns
- High percentage of unescaped output
- Use of dangerous function 'create_function'
- Missing nonce checks
- Missing capability checks
Super Widgets Security Vulnerabilities
Super Widgets Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Super Widgets Attack Surface
WordPress Hooks 3
Maintenance & Trust
Super Widgets Maintenance & Trust
Maintenance Signals
Community Trust
Super Widgets Alternatives
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
Featured Post Creative
featured-post-creative
Display Featured post on your website with 2 shortcode and 1 widget. Also work with Gutenberg shortcode block.
AK Featured Post Widget
akfeatured-post-widget
A widget that you can use to display your blog posts, custom post types, or woocommerce products!
Nelio Featured Posts
nelio-featured-posts
Select the featured posts you want to show at any time and include them in your theme using a widget.
Latest News Widget
latest-news-widget
A customizable latest news widget.
Super Widgets Developer Profile
2 plugins · 20 total installs
How We Detect Super Widgets
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/super-widgets/super-widgets.js/wp-content/plugins/super-widgets/super-widgets.csssuper-widgets.jssuper-widgets.css?ver=super-widgets.js?ver=HTML / DOM Fingerprints
super-widget-multi-postsuper-widget-multi-post-itemsuper-widget-single-postid="multi_post_super_widget"id="single_post_super_widget"id="single_taxonomy_super_widget"name="multi_post_super_widget"name="single_post_super_widget"name="single_taxonomy_super_widget"+11 morevar SUPER_WIDGETS_OPTIONS