WDS Multisite Aggregate Security & Risk Analysis

wordpress.org/plugins/wds-multisite-aggregate

A central area where all the posts on a WordPress MS network can be collected.

10 active installs v1.0.2 PHP + WP 3.0+ Updated Dec 10, 2016
wordpressmu
85
A · Safe
CVEs total1
Unpatched0
Last CVEJul 10, 2023
Safety Verdict

Is WDS Multisite Aggregate Safe to Use in 2026?

Generally Safe

Score 85/100

WDS Multisite Aggregate has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jul 10, 2023Updated 9yr ago
Risk Assessment

The wds-multisite-aggregate plugin v1.0.2 exhibits a generally positive security posture with several strengths. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events without authentication or permission checks indicates a limited attack surface, which is a good practice. The code also demonstrates a strong adherence to secure coding practices regarding SQL queries, with 85% utilizing prepared statements, and a reasonable 72% of output escaping being properly implemented. The fact that there are no taint analysis findings further suggests that complex vulnerabilities like arbitrary code execution or data leakage are unlikely within the current version's analyzed flows.

However, a significant concern remains the plugin's historical vulnerability record. It has a known medium severity CVE related to Cross-site Scripting, which was last patched relatively recently (July 2023). While currently unpatched CVEs are zero, this indicates a past tendency for vulnerabilities of this nature. The presence of a single external HTTP request, while not inherently bad, could be a vector for certain types of attacks if not handled with extreme care, though it is not flagged as a specific concern in the static analysis.

In conclusion, the plugin has made strides in reducing its immediate attack surface and implementing some secure coding practices. The primary weakness lies in its vulnerability history, suggesting a need for continued vigilance and thorough auditing. The lack of capability checks, while not leading to immediate deductions based on the provided data, could be a potential area for future security review if the plugin's functionality expands.

Key Concerns

  • Past medium severity CVE for XSS
  • No capability checks identified
Vulnerabilities
1 published

WDS Multisite Aggregate Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2015-10120medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WDS Multisite Aggregate <= 1.0.0 - Reflected Cross-Site Scripting

Jul 10, 2023 Patched in 1.0.1 (197d)
Version History

WDS Multisite Aggregate Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

WDS Multisite Aggregate Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
11 prepared
Unescaped Output
5
13 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

85% prepared13 total queries

Output Escaping

72% escaped18 total outputs
Attack Surface

WDS Multisite Aggregate Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionnetwork_admin_menuincludes/WDS_Multisite_Aggregate_Admin.php:18
actioninitincludes/WDS_Multisite_Aggregate_Admin.php:19
actionpost_submitbox_startincludes/WDS_Multisite_Aggregate_Debug.php:11
filterpost_linkincludes/WDS_Multisite_Aggregate_Frontend.php:15
filterpage_linkincludes/WDS_Multisite_Aggregate_Frontend.php:16
filterpost_thumbnail_htmlincludes/WDS_Multisite_Aggregate_Frontend.php:17
filtersitewide_tags_allowed_post_typesincludes/WDS_Multisite_Aggregate_Options.php:47
actionupdate_option_blog_publicincludes/WDS_Multisite_Aggregate_Remove.php:15
actiondelete_blogincludes/WDS_Multisite_Aggregate_Remove.php:18
actionarchive_blogincludes/WDS_Multisite_Aggregate_Remove.php:19
actiondeactivate_blogincludes/WDS_Multisite_Aggregate_Remove.php:20
actionmake_spam_blogincludes/WDS_Multisite_Aggregate_Remove.php:21
actionmature_blogincludes/WDS_Multisite_Aggregate_Remove.php:22
actiontransition_post_statusincludes/WDS_Multisite_Aggregate_Remove.php:24
actionsave_postwds-multisite-aggregate.php:79
actionwds_multisite_aggregate_post_syncwds-multisite-aggregate.php:80
actionwp_update_comment_countwds-multisite-aggregate.php:81
actiontrash_postwds-multisite-aggregate.php:83
actiondelete_postwds-multisite-aggregate.php:84
actioninitwds-multisite-aggregate.php:88
actionadmin_initwds-multisite-aggregate.php:91
actionall_admin_noticeswds-multisite-aggregate.php:98
Maintenance & Trust

WDS Multisite Aggregate Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedDec 10, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

WDS Multisite Aggregate Developer Profile

webdevstudios

10 plugins · 1.0M total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
642 days
View full developer profile
Detection Fingerprints

How We Detect WDS Multisite Aggregate

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wds-multisite-aggregate/assets/css/wds-multisite-aggregate.css/wp-content/plugins/wds-multisite-aggregate/assets/js/wds-multisite-aggregate.js
Script Paths
/wp-content/plugins/wds-multisite-aggregate/assets/js/wds-multisite-aggregate.js
Version Parameters
wds-multisite-aggregate/assets/css/wds-multisite-aggregate.css?ver=wds-multisite-aggregate/assets/js/wds-multisite-aggregate.js?ver=

HTML / DOM Fingerprints

CSS Classes
wds-multisite-aggregate-noticewds-multisite-aggregate-notice-descriptionwds-multisite-aggregate-redirect
HTML Comments
Copyright 2008 Donncha O Caoimh (http://ocaoimh.ie/)With contributions by Ron Rennick(http://wpmututorials.com/), Thomas Schneider(http://www.im-web-gefunden.de/) and others.This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License as published by+9 more
Data Attributes
data-wds-aggregate-debug
JS Globals
WDS_Multisite_Aggregatewds_ma_autoload_classes
FAQ

Frequently Asked Questions about WDS Multisite Aggregate