
Tidy Archives Security & Risk Analysis
wordpress.org/plugins/tidy-archivesTidy Archives displays your archives in a more practical way.
Is Tidy Archives Safe to Use in 2026?
Generally Safe
Score 100/100Tidy Archives has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tidy-archives" v1.0 plugin exhibits a generally good security posture with a zero attack surface, meaning it does not expose any direct entry points through AJAX, REST API, shortcodes, or cron events without proper authentication or permission checks. Furthermore, the absence of critical or high-severity taint flows and known CVEs suggests a level of code maturity and a lack of historically exploited vulnerabilities. The plugin also avoids dangerous functions and external HTTP requests, further contributing to its secure design.
Key Concerns
- Output escaping not implemented
- SQL queries not consistently prepared
- No nonce checks
- No capability checks
Tidy Archives Security Vulnerabilities
Tidy Archives Code Analysis
SQL Query Safety
Output Escaping
Tidy Archives Attack Surface
Maintenance & Trust
Tidy Archives Maintenance & Trust
Maintenance Signals
Community Trust
Tidy Archives Alternatives
Disable Author Archives
disable-author-archives
Disable Author Archives completely removes author archives and makes the web server return status code 404 ('Not Found') instead.
Simple Yearly Archive
simple-yearly-archive
Simple Yearly Archive is a rather neat and simple Wordpress plugin that allows you to display your archives in a year-based list.
Advanced Posts/Page
advanced-posts-per-page
Fine grained control of how many of your posts appear on each of the various WordPress archive pages.
Collapsing Archives
collapsing-archives
This plugin uses Javascript to dynamically expand or collapse the set of months for each year and posts for each month in the archive listing of your …
Sitekit
sitekit
Widgets: search, archives and categories. Shortcodes: archives, bloginfo, iframe and categories.
Tidy Archives Developer Profile
6 plugins · 340 total installs
How We Detect Tidy Archives
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<ul><li><a href=""></a></li>