
Website Toolbox Forum Security & Risk Analysis
wordpress.org/plugins/website-toolbox-forumsEffortlessly build a beautiful discussion forum with instant setup, seamless embedding, and exceptional support.
Is Website Toolbox Forum Safe to Use in 2026?
Generally Safe
Score 99/100Website Toolbox Forum has a strong security track record. Known vulnerabilities have been patched promptly.
The website-toolbox-forums plugin version 2.1.4 exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of immediately exploitable entry points with 0 unprotected AJAX handlers, REST API routes, shortcodes, or cron events. The majority of SQL queries (93%) and output operations (92%) utilize prepared statements and proper escaping, respectively, which are good security practices. The presence of 27 nonce checks and 7 capability checks also suggests an effort towards securing sensitive operations. However, the plugin does have some areas of concern. The taint analysis flagged 2 flows with unsanitized paths, indicating potential risks for path traversal or file manipulation vulnerabilities, even though they are not classified as critical or high severity. The vulnerability history shows a past medium-severity Cross-Site Scripting (XSS) vulnerability, and while there are no currently unpatched CVEs, this history suggests the plugin has had exploitable weaknesses in the past. The single file operation and 13 external HTTP requests, while not inherently insecure, represent potential attack vectors if not handled with extreme care and proper validation. In conclusion, while the plugin has made strides in securing its core functionalities, the presence of unsanitized paths and the past XSS vulnerability warrant careful monitoring and potential updates.
Key Concerns
- Taint analysis found unsanitized paths
- History of medium severity CVE (XSS)
- File operations detected
- External HTTP requests detected
Website Toolbox Forum Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Website Toolbox Community <= 2.0.1 - Reflected Cross-Site Scripting via websitetoolbox_username
Website Toolbox Forum Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Website Toolbox Forum Attack Surface
WordPress Hooks 58
Maintenance & Trust
Website Toolbox Forum Maintenance & Trust
Maintenance Signals
Community Trust
Website Toolbox Forum Alternatives
Discussion Board – WordPress Forum Plugin
wp-discussion-board
Discussion Board is a simple, effective way to add a forum or discussion board to your site, helping you build and engage an active community.
Private groups
bbp-private-groups
For bbPress - Creates private forum groups
Groups bbPress
groups-bbpress
Protect bbPress Forums, Topics and Replies using Groups.
BuddyPress Forums – Move Topic (Planned: Split and Merge Topic)
buddypress-forums-move-topic-planned-split-and-merge-topic
Provides a drop-down on Forum Topic page so Group Admins / Moderators can move topic thread to another forum. Generates email alert to topic author.
Group Forum Crumbs
group-forum-crumbs
Breadcrumbs for BuddyPress group forums.
Website Toolbox Forum Developer Profile
2 plugins · 90 total installs
How We Detect Website Toolbox Forum
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/website-toolbox-forums/core/client-info.js///js/mb/embed.jswebsite-toolbox-forums/core/client-info.js?ver=HTML / DOM Fingerprints
nocommentsid="embedded_forum"id="wtEmbedCode"window.embedded_forum