WDV One Page Docs – Documentation Plugin for WordPress Security & Risk Analysis

wordpress.org/plugins/wdv-one-page-docs

A one page documentation plugin for WordPress.

0 active installs v1.2.4 PHP 7.0+ WP 5.2+ Updated Unknown
docsdocumentdocumentationfaqknowledge-base
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJan 15, 2026
Safety Verdict

Is WDV One Page Docs – Documentation Plugin for WordPress Safe to Use in 2026?

Mostly Safe

Score 78/100

WDV One Page Docs – Documentation Plugin for WordPress is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Jan 15, 2026
Risk Assessment

The plugin "wdv-one-page-docs" v1.2.4 exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no identified AJAX handlers or REST API routes that are unprotected. Furthermore, there are no dangerous functions, file operations, or external HTTP requests, which are all good indicators. However, the code signals raise significant concerns, particularly the low percentage of properly escaped output (36%) and the complete absence of nonce checks. The data also indicates that 25% of SQL queries are not using prepared statements, which could lead to SQL injection vulnerabilities.

The vulnerability history is a major red flag. The plugin has a known medium severity CVE that is currently unpatched, and the common vulnerability type being "Missing Authorization" in the past suggests a pattern of insecure access control. This, combined with the static analysis findings of no nonce checks and limited capability checks, points to a potential for privilege escalation or unauthorized data access if an attacker can exploit these weaknesses or the unpatched CVE.

In conclusion, while the plugin has some strengths in its limited attack surface and absence of certain dangerous functions, the low output escaping, lack of nonce checks, non-prepared SQL queries, and critically, the unpatched medium severity CVE with a history of authorization issues, present significant risks. Users should be cautious and prioritize patching the known vulnerability and addressing the identified code weaknesses.

Key Concerns

  • Unpatched medium severity CVE
  • Low output escaping (36%)
  • No nonce checks
  • 25% of SQL queries not prepared
  • Limited capability checks (2)
Vulnerabilities
1

WDV One Page Docs – Documentation Plugin for WordPress Security Vulnerabilities

CVEs by Year

1 CVE in 2026 · unpatched
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-68896medium · 5.3Missing Authorization

WDV One Page Docs <= 1.2.4 - Missing Authorization

Jan 15, 2026Unpatched
Code Analysis
Analyzed Mar 17, 2026

WDV One Page Docs – Documentation Plugin for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
6 prepared
Unescaped Output
18
10 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

75% prepared8 total queries

Output Escaping

36% escaped28 total outputs
Attack Surface

WDV One Page Docs – Documentation Plugin for WordPress Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[wdvdoc] includes\class-wdv-one-page-doc-shortcode.php:9
[wdvdocs] includes\class-wdv-one-page-docs-shortcode.php:9
WordPress Hooks 9
actionplugins_loadedincludes\class-wdv-one-page-docs.php:151
actionadmin_enqueue_scriptsincludes\class-wdv-one-page-docs.php:166
actionadmin_enqueue_scriptsincludes\class-wdv-one-page-docs.php:167
actionadmin_menuincludes\class-wdv-one-page-docs.php:170
actionrest_api_initincludes\class-wdv-one-page-docs.php:172
actioninitincludes\class-wdv-one-page-docs.php:175
actionwp_enqueue_scriptsincludes\class-wdv-one-page-docs.php:191
actionwp_enqueue_scriptsincludes\class-wdv-one-page-docs.php:192
actioninitincludes\class-wdv-one-page-docs.php:195
Maintenance & Trust

WDV One Page Docs – Documentation Plugin for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WDV One Page Docs – Documentation Plugin for WordPress Developer Profile

vrpr

6 plugins · 1K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WDV One Page Docs – Documentation Plugin for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wdv-one-page-docs/css/wdv-one-page-docs-admin.css/wp-content/plugins/wdv-one-page-docs/js/wdv-one-page-docs-admin.js/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/styles.d15603a5505486538cae.css/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/runtime-es2015.0dae8cbc97194c7caed4.js/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/polyfills-es2015.f332a089ad1600448873.js/wp-content/plugins/wdv-one-page-docs/includes/wdv-table/dist/wdv-table/main-es2015.39610d7f768870db9733.js
Script Paths
/wp-content/plugins/wdv-one-page-docs/js/wdv-one-page-docs-admin.js
Version Parameters
wdv-one-page-docs-admin.css?ver=wdv-one-page-docs-admin.js?ver=styles.d15603a5505486538cae.css?ver=runtime-es2015.0dae8cbc97194c7caed4.js?ver=polyfills-es2015.f332a089ad1600448873.js?ver=main-es2015.39610d7f768870db9733.js?ver=

HTML / DOM Fingerprints

CSS Classes
wdv-one-page-docs
Data Attributes
data-wdv-docs-post-type
JS Globals
wdv_one_page_docs_admin
REST Endpoints
/wp-json/wdv-one-page-docs/v1/posts
Shortcode Output
[wdv_one_page_docs_shortcode]
FAQ

Frequently Asked Questions about WDV One Page Docs – Documentation Plugin for WordPress