w2pe Measurement Widget Security & Risk Analysis

wordpress.org/plugins/w2pe-measurement-widget

w2pe Measurement Widget is especially designed to make your units conversion job a whole lot easier. Here you'll find instant conversions for tho …

10 active installs v1.00 PHP + WP 3.7+ Updated Mar 12, 2014
distance-convertermeasuretemperature-converterunit-conversionunit-converter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is w2pe Measurement Widget Safe to Use in 2026?

Generally Safe

Score 85/100

w2pe Measurement Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The w2pe-measurement-widget plugin version 1.00 exhibits several significant security concerns despite having no recorded vulnerability history. The most alarming aspect is the large attack surface, with 4 out of 5 entry points lacking any form of authentication or authorization checks. This means that any unauthenticated user could potentially interact with these AJAX handlers, leading to unintended actions or information disclosure. Furthermore, the taint analysis reveals 2 flows with unsanitized paths, one of which is classified as high severity. This indicates a risk of attackers being able to inject malicious data that is not properly validated before being processed, potentially leading to code execution or other severe vulnerabilities. The code analysis also highlights a concerning lack of proper output escaping, with only 7% of outputs being correctly escaped. This significantly increases the risk of cross-site scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the website that are then executed in the browsers of other users. While the plugin has no known CVEs, this can often be due to a lack of rigorous security auditing or the vulnerabilities simply not having been discovered or publicly disclosed yet. The overall security posture is weak due to the numerous unprotected entry points, high-severity taint flows, and pervasive lack of output escaping, which outweigh the absence of known historical vulnerabilities.

Key Concerns

  • Unprotected AJAX handlers
  • High severity taint flow
  • Unsanitized paths in taint flows
  • Low output escaping percentage
  • Missing nonce checks on AJAX
  • Missing capability checks
  • SQL queries not using prepared statements
Vulnerabilities
None known

w2pe Measurement Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

w2pe Measurement Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
3 prepared
Unescaped Output
43
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

33% prepared9 total queries

Output Escaping

7% escaped46 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
<category> (category.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

w2pe Measurement Widget Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

authwp_ajax_w2p_measure_categoryindex.php:146
noprivwp_ajax_w2p_measure_categoryindex.php:148
authwp_ajax_w2p_measure_unit1index.php:169
noprivwp_ajax_w2p_measure_unit1index.php:171

Shortcodes 1

[w2pe_measurement] index.php:200
WordPress Hooks 3
actionadmin_menuindex.php:108
actionwp_headindex.php:135
actionwidgets_initwidget.php:96
Maintenance & Trust

w2pe Measurement Widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedMar 12, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings4
Active installs10
Developer Profile

w2pe Measurement Widget Developer Profile

wppluginexpert

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect w2pe Measurement Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/w2pe-measurement-widget/units.php/wp-content/plugins/w2pe-measurement-widget/category.php/wp-content/plugins/w2pe-measurement-widget/widget.php/wp-content/plugins/w2pe-measurement-widget/page.php/wp-content/plugins/w2pe-measurement-widget/support.php/wp-content/plugins/w2pe-measurement-widget/images/menu.png/wp-content/plugins/w2pe-measurement-widget/files/w2pe_measure.css/wp-content/plugins/w2pe-measurement-widget/files/w2pe_measure.js

HTML / DOM Fingerprints

JS Globals
ajaxurl
Shortcode Output
[w2pe_measurement]
FAQ

Frequently Asked Questions about w2pe Measurement Widget