
WDV One Page Docs – Documentation Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/wdv-one-page-docsA one page documentation plugin for WordPress.
Is WDV One Page Docs – Documentation Plugin for WordPress Safe to Use in 2026?
Mostly Safe
Score 70/100WDV One Page Docs – Documentation Plugin for WordPress is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The plugin "wdv-one-page-docs" v1.2.4 exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no identified AJAX handlers or REST API routes that are unprotected. Furthermore, there are no dangerous functions, file operations, or external HTTP requests, which are all good indicators. However, the code signals raise significant concerns, particularly the low percentage of properly escaped output (36%) and the complete absence of nonce checks. The data also indicates that 25% of SQL queries are not using prepared statements, which could lead to SQL injection vulnerabilities.
The vulnerability history is a major red flag. The plugin has a known medium severity CVE that is currently unpatched, and the common vulnerability type being "Missing Authorization" in the past suggests a pattern of insecure access control. This, combined with the static analysis findings of no nonce checks and limited capability checks, points to a potential for privilege escalation or unauthorized data access if an attacker can exploit these weaknesses or the unpatched CVE.
In conclusion, while the plugin has some strengths in its limited attack surface and absence of certain dangerous functions, the low output escaping, lack of nonce checks, non-prepared SQL queries, and critically, the unpatched medium severity CVE with a history of authorization issues, present significant risks. Users should be cautious and prioritize patching the known vulnerability and addressing the identified code weaknesses.
Key Concerns
- Unpatched medium severity CVE
- Low output escaping (36%)
- No nonce checks
- 25% of SQL queries not prepared
- Limited capability checks (2)
WDV One Page Docs – Documentation Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WDV One Page Docs <= 1.2.4 - Missing Authorization
WDV One Page Docs – Documentation Plugin for WordPress Release Timeline
WDV One Page Docs – Documentation Plugin for WordPress Code Analysis
SQL Query Safety
Output Escaping
WDV One Page Docs – Documentation Plugin for WordPress Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
WDV One Page Docs – Documentation Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
WDV One Page Docs – Documentation Plugin for WordPress Alternatives
BetterDocs – Knowledge Base Docs & FAQ Solution for Elementor & Block Editor
betterdocs
A full-featured documentation plugin including AI writing assistance to create knowledge bases, docs, FAQs, wikis, and more with easy drag & drop UI.
Easy Docs
easy-docs
Easy Docs simplifies creating and displaying documentation. It lets you organize content into folders like structure and display it via shortcode.
DoC8
doc8
Show your documented project, user guide, or any other type of project you have that require upfront documentation with this simple but flexible inter …
Echo Knowledge Base – Documentation, FAQs, Chat & Smart Search
echo-knowledge-base
A fully featured, easy-to-use documentation plugin with AI chat, search, FAQs, and quizzes. Build beautiful knowledge bases, docs, and wikis.
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
wedocs
Build a powerful documentation hub with an AI-powered knowledge base, docs, wiki tools, and an AI chatbot to help users find answers instantly.
WDV One Page Docs – Documentation Plugin for WordPress Developer Profile
7 plugins · 1K total installs
How We Detect WDV One Page Docs – Documentation Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wdv-one-page-docs/css/wdv-one-page-docs-admin.css/wp-content/plugins/wdv-one-page-docs/js/wdv-one-page-docs-admin.js/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/styles.d15603a5505486538cae.css/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/runtime-es2015.0dae8cbc97194c7caed4.js/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/polyfills-es2015.f332a089ad1600448873.js/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/main-es2015.39610d7f768870db9733.js/wp-content/plugins/wdv-one-page-docs/js/wdv-one-page-docs-admin.jswdv-one-page-docs-admin.css?ver=wdv-one-page-docs-admin.js?ver=styles.d15603a5505486538cae.css?ver=runtime-es2015.0dae8cbc97194c7caed4.js?ver=polyfills-es2015.f332a089ad1600448873.js?ver=main-es2015.39610d7f768870db9733.js?ver=HTML / DOM Fingerprints
wdv-one-page-docsdata-wdv-docs-post-typewdv_one_page_docs_admin/wp-json/wdv-one-page-docs/v1/posts[wdv_one_page_docs_shortcode]