
Switch Pages Security & Risk Analysis
wordpress.org/plugins/switch-pagesSwitch Pages is a plugin which allows you to switch between pages/posts from within the Edit page without having to go to the Pages tab and searching …
Is Switch Pages Safe to Use in 2026?
Generally Safe
Score 85/100Switch Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'switch-pages' v2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any registered AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals show no dangerous functions, file operations, or external HTTP requests. The sole SQL query identified is correctly using prepared statements, which is a positive security practice. The vulnerability history is also clear, with no known CVEs, which suggests a good track record.
However, there are critical concerns regarding output escaping. With two total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from external sources or even internal plugin logic could be maliciously crafted to execute arbitrary JavaScript. The complete lack of nonce checks and capability checks, coupled with an attack surface of zero unprotected entry points, means that while the entry points themselves might be secure, the data processed through them is not protected from manipulation if an attacker can find a way to inject data or trigger plugin functionality.
In conclusion, while the plugin excels at limiting its direct attack vectors and handling database operations securely, the lack of output escaping presents a significant and easily exploitable vulnerability. The absence of recorded vulnerabilities historically is encouraging but does not negate the immediate risk posed by the unescaped output. This plugin should be treated with caution until the output escaping issue is addressed.
Key Concerns
- Output not properly escaped
- No nonce checks on potential inputs
- No capability checks on potential inputs
Switch Pages Security Vulnerabilities
Switch Pages Code Analysis
SQL Query Safety
Output Escaping
Switch Pages Attack Surface
WordPress Hooks 4
Maintenance & Trust
Switch Pages Maintenance & Trust
Maintenance Signals
Community Trust
Switch Pages Alternatives
Fast Page Switch
fast-page-switch
Save time switching between posts of any post-type in wp-admin.
azurecurve Series Index
azurecurve-series-index
Displays Index of Series Posts using series-index Shortcode. This plugin is multi-site compatible and contains an inbuilt show/hide toggle.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
Duplicate Post
copy-delete-posts
Duplicate post
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
Switch Pages Developer Profile
5 plugins · 2K total installs
How We Detect Switch Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/switch-pages/switch-pages-sidebar.css/wp-content/plugins/switch-pages/js/sidebar.js/wp-content/plugins/switch-pages/js/sidebar.jsHTML / DOM Fingerprints
switch_pages_title/wp-json/wp/v2/posts?switch_pages_title=