
WDV One Page Docs – Documentation Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/wdv-one-page-docsA one page documentation plugin for WordPress.
Is WDV One Page Docs – Documentation Plugin for WordPress Safe to Use in 2026?
Mostly Safe
Score 78/100WDV One Page Docs – Documentation Plugin for WordPress is generally safe to use. 1 past CVE were resolved. Keep it updated.
The plugin "wdv-one-page-docs" v1.2.4 exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no identified AJAX handlers or REST API routes that are unprotected. Furthermore, there are no dangerous functions, file operations, or external HTTP requests, which are all good indicators. However, the code signals raise significant concerns, particularly the low percentage of properly escaped output (36%) and the complete absence of nonce checks. The data also indicates that 25% of SQL queries are not using prepared statements, which could lead to SQL injection vulnerabilities.
The vulnerability history is a major red flag. The plugin has a known medium severity CVE that is currently unpatched, and the common vulnerability type being "Missing Authorization" in the past suggests a pattern of insecure access control. This, combined with the static analysis findings of no nonce checks and limited capability checks, points to a potential for privilege escalation or unauthorized data access if an attacker can exploit these weaknesses or the unpatched CVE.
In conclusion, while the plugin has some strengths in its limited attack surface and absence of certain dangerous functions, the low output escaping, lack of nonce checks, non-prepared SQL queries, and critically, the unpatched medium severity CVE with a history of authorization issues, present significant risks. Users should be cautious and prioritize patching the known vulnerability and addressing the identified code weaknesses.
Key Concerns
- Unpatched medium severity CVE
- Low output escaping (36%)
- No nonce checks
- 25% of SQL queries not prepared
- Limited capability checks (2)
WDV One Page Docs – Documentation Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WDV One Page Docs <= 1.2.4 - Missing Authorization
WDV One Page Docs – Documentation Plugin for WordPress Code Analysis
SQL Query Safety
Output Escaping
WDV One Page Docs – Documentation Plugin for WordPress Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
WDV One Page Docs – Documentation Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
WDV One Page Docs – Documentation Plugin for WordPress Alternatives
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor
betterdocs
A full-featured documentation plugin including AI writing assistance to create knowledge bases, docs, FAQs, wikis, and more with easy drag & drop UI.
Easy Docs
easy-docs
Easy Docs simplifies creating and displaying documentation. It lets you organize content into folders like structure and display it via shortcode.
Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search
echo-knowledge-base
A fully featured, easy-to-use documentation plugin with AI chat and search integration. Build beautiful knowledge bases, FAQs, docs, and wikis.
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
wedocs
Build AI-powered documentation hub with knowledge base, docs, wiki tools and chatbot support with weDocs, built by weDevs with 13 years of innovation.
Knowledge Base documentation & wiki plugin – BasePress Docs
basepress
Easily create & manage documentation. Reduce support tickets & scale your customer support workload. This simple plugin works with any theme.
WDV One Page Docs – Documentation Plugin for WordPress Developer Profile
6 plugins · 1K total installs
How We Detect WDV One Page Docs – Documentation Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wdv-one-page-docs/css/wdv-one-page-docs-admin.css/wp-content/plugins/wdv-one-page-docs/js/wdv-one-page-docs-admin.js/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/styles.d15603a5505486538cae.css/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/runtime-es2015.0dae8cbc97194c7caed4.js/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/polyfills-es2015.f332a089ad1600448873.js/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/main-es2015.39610d7f768870db9733.js/wp-content/plugins/wdv-one-page-docs/js/wdv-one-page-docs-admin.jswdv-one-page-docs-admin.css?ver=wdv-one-page-docs-admin.js?ver=styles.d15603a5505486538cae.css?ver=runtime-es2015.0dae8cbc97194c7caed4.js?ver=polyfills-es2015.f332a089ad1600448873.js?ver=main-es2015.39610d7f768870db9733.js?ver=HTML / DOM Fingerprints
wdv-one-page-docsdata-wdv-docs-post-typewdv_one_page_docs_admin/wp-json/wdv-one-page-docs/v1/posts[wdv_one_page_docs_shortcode]