
Widget Pack Security & Risk Analysis
wordpress.org/plugins/ts-widget-packWidget Pack is a WordPress plugin that enables essential, yet powerful features for your website.
Is Widget Pack Safe to Use in 2026?
Generally Safe
Score 85/100Widget Pack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ts-widget-pack" v1.2 plugin exhibits a mixed security posture. On the positive side, there are no known CVEs, no raw SQL queries, and no file operations or external HTTP requests, suggesting a potentially clean codebase in these areas. The complete absence of attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events is also a strong indicator of reduced exposure. However, significant concerns arise from the static analysis. The presence of six instances of the `create_function` is a critical red flag, as this function is deprecated and considered a security risk due to its ability to execute arbitrary code. Furthermore, the alarmingly low rate of proper output escaping (only 9%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, where user-supplied data might be rendered without sanitization. The lack of nonce and capability checks on all entry points (though the attack surface is zero), if any were present, would further exacerbate these risks.
Given the complete lack of vulnerability history, it's difficult to definitively assess long-term maintenance and security diligence. This could indicate either a historically secure plugin or a lack of historical security scrutiny. The current static analysis, however, highlights critical weaknesses in code execution and output sanitization that pose immediate risks. The use of `create_function` is a severe concern that should be addressed immediately, and the poor output escaping practices necessitate thorough review and remediation to prevent XSS attacks. The absence of known vulnerabilities is positive, but it does not negate the serious security flaws identified in the current code.
Key Concerns
- Dangerous function create_function usage
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
Widget Pack Security Vulnerabilities
Widget Pack Code Analysis
Dangerous Functions Found
Output Escaping
Widget Pack Attack Surface
WordPress Hooks 8
Maintenance & Trust
Widget Pack Maintenance & Trust
Maintenance Signals
Community Trust
Widget Pack Alternatives
Nested Pages
wp-nested-pages
Nested Pages provides a drag and drop interface for managing pages & posts in the WordPress admin, while maintaining quick edit functionality.
Embed PDF Viewer
embed-pdf-viewer
Embed a PDF from the Media Library or elsewhere via oEmbed or as a block into an iframe tag.
Admin Menu Tree Page View
admin-menu-tree-page-view
Get a tree view of all your pages directly in the admin menu. Search, add, edit, view, re-order – all is just one click away!
Disable Embeds
disable-embeds
Don’t like the enhanced embeds in WordPress 4.4? Easily disable the feature using this plugin.
Embed Privacy
embed-privacy
Embed Privacy prevents the loading of embedded external content and allows your site visitors to opt-in.
Widget Pack Developer Profile
5 plugins · 2K total installs
How We Detect Widget Pack
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ts-widget-pack/css/ts-widget-pack.css/wp-content/plugins/ts-widget-pack/css/ts-widget-pack.min.css/wp-content/plugins/ts-widget-pack/js/ts-widget-pack.js/wp-content/plugins/ts-widget-pack/js/ts-widget-pack.min.js/wp-content/plugins/ts-widget-pack/js/ts-widget-pack.js/wp-content/plugins/ts-widget-pack/js/ts-widget-pack.min.jsts-widget-pack?ver=ts-widget-pack.css?ver=ts-widget-pack.min.css?ver=ts-widget-pack.js?ver=ts-widget-pack.min.js?ver=HTML / DOM Fingerprints
ts-widget-pack-call-to-actionts-widget-pack-page-treets-widget-pack-list-authorsts-widget-pack-preview-postts-widget-pack-social-iconsts-widget-pack-oembeddata-ts-widget-pack