Swift Todo List Security & Risk Analysis

wordpress.org/plugins/swift-todolist

A simple and customizable to-do list plugin for WordPress that allows users to create, update, view, and delete tasks.

20 active installs v0.1.3 PHP + WP 5.0+ Updated Nov 7, 2024
shortcodetask-managementtaskstodowoocommerce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Swift Todo List Safe to Use in 2026?

Generally Safe

Score 92/100

Swift Todo List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The swift-todolist v0.1.3 plugin exhibits a generally strong security posture based on the provided static analysis. The plugin has a moderate attack surface consisting of AJAX handlers and shortcodes, but importantly, all identified entry points appear to have some form of authorization check, which is a significant positive. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests further bolsters its security. Nonce checks are present, though not on all entry points, which is a minor concern. The most notable weakness identified is the moderate rate of unescaped output (38%), which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly handled before being displayed. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a history of responsible development or simply a lack of publicly discovered vulnerabilities. While the lack of known vulnerabilities is positive, the presence of unescaped output represents a tangible risk that should be addressed to achieve a truly robust security profile.

Key Concerns

  • Significant portion of output not properly escaped
  • Nonce checks missing on some entry points
Vulnerabilities
None known

Swift Todo List Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Swift Todo List Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
42 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

62% escaped68 total outputs
Attack Surface

Swift Todo List Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 6

authwp_ajax_create_taskinclude\task-handlers\create.php:9
noprivwp_ajax_create_taskinclude\task-handlers\create.php:10
authwp_ajax_remove_taskinclude\task-handlers\remove.php:9
noprivwp_ajax_remove_taskinclude\task-handlers\remove.php:10
authwp_ajax_update_taskinclude\task-handlers\update.php:9
noprivwp_ajax_update_taskinclude\task-handlers\update.php:10

Shortcodes 1

[swift_todolist] include\class-swift-todolist.php:29
WordPress Hooks 6
actioninitinclude\class-swift-todolist.php:12
actionwp_enqueue_scriptsinclude\class-swift-todolist.php:13
filterquery_varsinclude\class-swift-todolist.php:33
filtertemplate_redirectinclude\class-swift-todolist.php:44
actionwoocommerce_account_dashboardinclude\class-swift-todolist.php:53
filtertemplate_redirectinclude\class-swift-todolist.php:56
Maintenance & Trust

Swift Todo List Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 7, 2024
PHP min version
Downloads701

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Swift Todo List Developer Profile

Shayan Ghiaseddin

2 plugins · 30 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Swift Todo List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/swift-todolist/assets/css/swift-todolist.css/wp-content/plugins/swift-todolist/assets/js/swift-todolist.js/wp-content/plugins/swift-todolist/assets/css/dashicons.css
Script Paths
/wp-content/plugins/swift-todolist/assets/js/swift-todolist.js
Version Parameters
swift-todolist/assets/js/swift-todolist.js?ver=swift-todolist/assets/css/swift-todolist.css?ver=swift-todolist/assets/css/dashicons.css?ver=

HTML / DOM Fingerprints

CSS Classes
goto-todolist-page
JS Globals
swiftTodoList
Shortcode Output
<a href="
FAQ

Frequently Asked Questions about Swift Todo List