
w2pe Measurement Widget Security & Risk Analysis
wordpress.org/plugins/w2pe-measurement-widgetw2pe Measurement Widget is especially designed to make your units conversion job a whole lot easier. Here you'll find instant conversions for tho …
Is w2pe Measurement Widget Safe to Use in 2026?
Generally Safe
Score 85/100w2pe Measurement Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The w2pe-measurement-widget plugin version 1.00 exhibits several significant security concerns despite having no recorded vulnerability history. The most alarming aspect is the large attack surface, with 4 out of 5 entry points lacking any form of authentication or authorization checks. This means that any unauthenticated user could potentially interact with these AJAX handlers, leading to unintended actions or information disclosure. Furthermore, the taint analysis reveals 2 flows with unsanitized paths, one of which is classified as high severity. This indicates a risk of attackers being able to inject malicious data that is not properly validated before being processed, potentially leading to code execution or other severe vulnerabilities. The code analysis also highlights a concerning lack of proper output escaping, with only 7% of outputs being correctly escaped. This significantly increases the risk of cross-site scripting (XSS) vulnerabilities, where attackers could inject malicious scripts into the website that are then executed in the browsers of other users. While the plugin has no known CVEs, this can often be due to a lack of rigorous security auditing or the vulnerabilities simply not having been discovered or publicly disclosed yet. The overall security posture is weak due to the numerous unprotected entry points, high-severity taint flows, and pervasive lack of output escaping, which outweigh the absence of known historical vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow
- Unsanitized paths in taint flows
- Low output escaping percentage
- Missing nonce checks on AJAX
- Missing capability checks
- SQL queries not using prepared statements
w2pe Measurement Widget Security Vulnerabilities
w2pe Measurement Widget Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
w2pe Measurement Widget Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
w2pe Measurement Widget Maintenance & Trust
Maintenance Signals
Community Trust
w2pe Measurement Widget Alternatives
Metric Converter
metric-converter
Metric Converter is a WP extension for the visual editor that allows to convert metric units to American linear measures (inch, oz, lbs).
Unit Converter Pro
unit-converter-pro
This widget can be added anywhere in your site and provides a fully featured unit converter that can be used in various configurations.
WP Unit Converter
wp-unit-converter
WP Unit Converter allows you to convert Length/Distance, Temperature, Time, Weight, Area and Speed metrics in different units of measurement.
Smart Convert – Currency & Unit Conversion
smart-convert-currency-unit-conversion
The ultimate conversion engine: 153 Currencies, 105+ Units, Custom Unit Builder, GeoIP detection, and a native Gutenberg Block with live previews.
Performance Lab
performance-lab
Performance plugin from the WordPress Performance Team, which is a collection of standalone performance features.
w2pe Measurement Widget Developer Profile
2 plugins · 20 total installs
How We Detect w2pe Measurement Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/w2pe-measurement-widget/units.php/wp-content/plugins/w2pe-measurement-widget/category.php/wp-content/plugins/w2pe-measurement-widget/widget.php/wp-content/plugins/w2pe-measurement-widget/page.php/wp-content/plugins/w2pe-measurement-widget/support.php/wp-content/plugins/w2pe-measurement-widget/images/menu.png/wp-content/plugins/w2pe-measurement-widget/files/w2pe_measure.css/wp-content/plugins/w2pe-measurement-widget/files/w2pe_measure.jsHTML / DOM Fingerprints
ajaxurl[w2pe_measurement]