VikWidgetsLoader – Collection of Widgets Security & Risk Analysis

wordpress.org/plugins/vikwidgetsloader

A variety of Widgets to enhance your website. Add sliders, grids and icons to your pages.

1K active installs v1.10.1 PHP 5.4.0+ WP 4.7+ Updated Dec 6, 2022
cookiesmapsslidervikwidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is VikWidgetsLoader – Collection of Widgets Safe to Use in 2026?

Generally Safe

Score 85/100

VikWidgetsLoader – Collection of Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'vikwidgetsloader' v1.10.1 demonstrates a generally good security posture, with no known vulnerabilities or critical code signals indicating immediate threats. The absence of detected dangerous functions, raw SQL queries, external HTTP requests, and taint analysis findings is positive. However, a significant concern arises from the low percentage (21%) of properly escaped output. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might be rendered without proper sanitization, allowing attackers to inject malicious scripts.

The plugin's attack surface appears minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. This limits the potential entry points for attackers. The presence of a bundled library, Select2, without specific version information, introduces a potential risk if that library itself has known vulnerabilities and is not updated by the plugin. Overall, while the plugin's core functionality seems secure, the lack of robust output escaping is a notable weakness that requires immediate attention to prevent potential XSS exploits.

Key Concerns

  • Low percentage of properly escaped output
  • Bundled library without version info
Vulnerabilities
None known

VikWidgetsLoader – Collection of Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

VikWidgetsLoader – Collection of Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
616
160 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

21% escaped776 total outputs
Attack Surface

VikWidgetsLoader – Collection of Widgets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actioninitvikwidgetsloader.php:21
actionwidgets_initvikwidgetsloader.php:22
actionwp_enqueue_scriptswidgets\vikwp_category_post\vikwp_category_post.php:21
actionwp_enqueue_scriptswidgets\vikwp_contentslider\vikwp_contentslider.php:30
actionwp_enqueue_scriptswidgets\vikwp_contentslider\vikwp_contentslider.php:39
actionwp_enqueue_scriptswidgets\vikwp_cookiespolicy\vikwp_cookiespolicy.php:21
actionwidgets_initwidgets\vikwp_counter\vikwp_counter.php:19
actionwp_enqueue_scriptswidgets\vikwp_counter\vikwp_counter.php:30
actionadmin_enqueue_scriptswidgets\vikwp_counter\vikwp_counter.php:44
actionwp_enqueue_scriptswidgets\vikwp_customtext\vikwp_customtext.php:21
actionwp_enqueue_scriptswidgets\vikwp_googlemaps\vikwp_googlemaps.php:19
actionwp_enqueue_scriptswidgets\vikwp_gridcontent\vikwp_gridcontent.php:21
actionwidgets_initwidgets\vikwp_icons\vikwp_icons.php:19
actionwp_enqueue_scriptswidgets\vikwp_icons\vikwp_icons.php:38
actionadmin_enqueue_scriptswidgets\vikwp_icons\vikwp_icons.php:52
actionwp_enqueue_scriptswidgets\vikwp_speakers\vikwp_speakers.php:28
actionwp_enqueue_scriptswidgets\vikwp_textslide\vikwp_textslide.php:28
actionwp_enqueue_scriptswidgets\vikwp_textslide\vikwp_textslide.php:35
actionadmin_enqueue_scriptswidgets\vikwp_textslide\vikwp_textslide.php:45
actionload-widgets.phpwidgets\vikwp_textslide\vikwp_textslide.php:53
Maintenance & Trust

VikWidgetsLoader – Collection of Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 6, 2022
PHP min version5.4.0
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs1K
Developer Profile

VikWidgetsLoader – Collection of Widgets Developer Profile

e4jvikwp

7 plugins · 16K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
244 days
View full developer profile
Detection Fingerprints

How We Detect VikWidgetsLoader – Collection of Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vikwidgetsloader/widgets/vikwp_category_post/vikwp_category_post.php/wp-content/plugins/vikwidgetsloader/widgets/vikwp_contentslider/vikwp_contentslider.php/wp-content/plugins/vikwidgetsloader/widgets/vikwp_cookiespolicy/vikwp_cookiespolicy.php/wp-content/plugins/vikwidgetsloader/widgets/vikwp_counter/vikwp_counter.php
Script Paths
/wp-content/plugins/vikwidgetsloader/widgets/vikwp_contentslider/vikwp_contentslider.php/wp-content/plugins/vikwidgetsloader/widgets/vikwp_counter/vikwp_counter.php
Version Parameters
vikwidgetsloader/style.css?ver=vikwidgetsloader/css/animate.css?ver=vikwidgetsloader/css/bootstrap.css?ver=vikwidgetsloader/css/bootstrap-touch-slider.css?ver=vikwidgetsloader/js/effects.js?ver=vikwidgetsloader/js/bootstrap.js?ver=vikwidgetsloader/js/bootstrap-touch-slider.js?ver=vikwidgetsloader/css/src/all.min.css?ver=vikwidgetsloader/js/select2/select2.min.js?ver=vikwidgetsloader/js/select2/select2.css?ver=

HTML / DOM Fingerprints

CSS Classes
vikwl-category-postvikwl-contentslidervikwl-cookiespolicyvikwl-countervikwl_counter_fontawesomevikwl_counter_select2
Data Attributes
data-widget-id="vikwp_category_post"data-widget-id="vikwp_contentslider"data-widget-id="vikwp_cookiespolicy"data-widget-id="vikwp_counter"
JS Globals
vikwl_stylesvikwp_contentslidervikwp_widgetsloaderanimatevikwp_widgetsloaderbootstrapvikwp_widgetsloadertouchslidercssvikwp_widgetsloadereffects+5 more
FAQ

Frequently Asked Questions about VikWidgetsLoader – Collection of Widgets