
Wayfinder Security & Risk Analysis
wordpress.org/plugins/wayfinderEasily identify and select blocks in use within the editor.
Is Wayfinder Safe to Use in 2026?
Generally Safe
Score 92/100Wayfinder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wayfinder" plugin v1.2.0 demonstrates a generally strong security posture based on the provided static analysis. The plugin has a remarkably small attack surface, with no detected AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks. The code also shows good practices in SQL query handling, exclusively using prepared statements, and a respectable number of capability checks and nonce checks are in place. File operations and external HTTP requests are absent, further reducing potential vulnerabilities.
However, the most significant area of concern lies in output escaping, where only 56% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data or plugin-generated content is not sufficiently sanitized before being displayed to users. While taint analysis shows no detected unsanitized paths, the low percentage of properly escaped output is a notable weakness.
The plugin's vulnerability history is clean, with no known CVEs, which is a positive sign. This, combined with the limited attack surface and focus on prepared statements, suggests a development team that is likely aware of common WordPress security pitfalls. Despite the clean history, the unescaped output remains the primary risk that should be addressed to further harden the plugin.
Key Concerns
- Output escaping is not fully implemented
Wayfinder Security Vulnerabilities
Wayfinder Code Analysis
Output Escaping
Wayfinder Attack Surface
WordPress Hooks 10
Maintenance & Trust
Wayfinder Maintenance & Trust
Maintenance Signals
Community Trust
Wayfinder Alternatives
Query Loop Post Selector
query-loop-post-selector
A native query loop extension that adds a new option in the filter that allows user to specifically pick certain posts to display
Blocks Detector Finder
blocks-detector-finder
Detect / Find Gutenberg Blocks used on pages, also detect not used Gutenberg Blocks or Missing Gutenberg Blocks.
DBlocks Finder. Blocks and Synced Patterns
dblocks-finder
DBlocks Finder is a WordPress plugin to easily find and manage Gutenberg blocks and synced patterns. Simple UI to find them across posts and pages.
Store Finder for WooCommerce – List Store Locations with Contact Info
store-finder
WooCommerce Plugin that Give your customer an easy to use interface to find all your store and store contact info.
Form Finder for Ninja Forms
form-finder-for-ninja-forms
Find every Ninja Forms embed across your site and review usage stats in a modern admin report.
Wayfinder Developer Profile
1 plugin · 800 total installs
How We Detect Wayfinder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wayfinder-admin-wrapdata-wayfinder-optiondata-wayfinder-value