Unlimited Page Sidebars Security & Risk Analysis

wordpress.org/plugins/unlimited-page-sidebars

Assign one specific widget area (sidebar) to each page.

100 active installs v0.2.8 PHP + WP 5.0+ Updated Unknown
cmspagessidebars
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 31, 2025
Safety Verdict

Is Unlimited Page Sidebars Safe to Use in 2026?

Generally Safe

Score 99/100

Unlimited Page Sidebars has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 31, 2025
Risk Assessment

The 'unlimited-page-sidebars' plugin, version 0.2.8, exhibits a mixed security posture. On the positive side, the static analysis reveals a commendable lack of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and file operations. Crucially, all identified AJAX entry points have associated nonce checks and capability checks, which is a strong indicator of good development practice in preventing unauthorized actions. The absence of direct REST API routes, shortcodes, and cron events also contributes to a reduced attack surface. However, a significant concern arises from the output escaping. With only 52% of outputs being properly escaped, there is a notable risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the site. The plugin's vulnerability history shows one known CVE, which was a Cross-Site Request Forgery (CSRF) vulnerability. While this CVE is reported as patched, the presence of past vulnerabilities, even if medium severity, suggests a history of security oversight. The lack of critical or high severity taint flows in the current analysis is a positive sign, but the unpatched CVE and the high percentage of unescaped output are areas requiring immediate attention. Overall, while the plugin demonstrates solid fundamental security practices in handling sensitive operations like database queries and authentication for entry points, the insufficient output escaping presents a tangible risk of XSS, and the past CVE indicates a need for continued vigilance.

Key Concerns

  • Significant portion of output not properly escaped
  • Previous CSRF vulnerability recorded
Vulnerabilities
1

Unlimited Page Sidebars Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22688medium · 6.1Cross-Site Request Forgery (CSRF)

Unlimited Page Sidebars <= 0.2.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Jan 31, 2025 Patched in 0.2.7 (4d)
Code Analysis
Analyzed Mar 16, 2026

Unlimited Page Sidebars Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
11 escaped
Nonce Checks
4
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

52% escaped21 total outputs
Attack Surface

Unlimited Page Sidebars Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_custom_sidebar_addunlimited-page-sidebars.php:98
authwp_ajax_custom_sidebar_renameunlimited-page-sidebars.php:99
authwp_ajax_custom_sidebar_removeunlimited-page-sidebars.php:100
authwp_ajax_custom_sidebar_listunlimited-page-sidebars.php:101
WordPress Hooks 7
filterplugin_action_linksunlimited-page-sidebars.php:23
actionadmin_initunlimited-page-sidebars.php:25
actionadmin_menuunlimited-page-sidebars.php:27
actionadmin_menuunlimited-page-sidebars.php:29
actionsave_postunlimited-page-sidebars.php:31
filtersidebars_widgetsunlimited-page-sidebars.php:33
actioninitunlimited-page-sidebars.php:546
Maintenance & Trust

Unlimited Page Sidebars Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version
Downloads9K

Community Trust

Rating100/100
Number of ratings5
Active installs100
Developer Profile

Unlimited Page Sidebars Developer Profile

Ederson Peka

6 plugins · 540 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
742 days
View full developer profile
Detection Fingerprints

How We Detect Unlimited Page Sidebars

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unlimited-page-sidebars/css/admin.css/wp-content/plugins/unlimited-page-sidebars/js/admin.js
Script Paths
/wp-content/plugins/unlimited-page-sidebars/js/admin.js
Version Parameters
unlimited-page-sidebars/css/admin.cssunlimited-page-sidebars/js/admin.js

HTML / DOM Fingerprints

CSS Classes
custom_sidebar
JS Globals
unlimited_page_sidebars
FAQ

Frequently Asked Questions about Unlimited Page Sidebars