Website Toolbox Forum Security & Risk Analysis

wordpress.org/plugins/website-toolbox-forums

Effortlessly build a beautiful discussion forum with instant setup, seamless embedding, and exceptional support.

80 active installs v2.1.4 PHP + WP 3.0.0+ Updated Mar 8, 2026
discussion-boardforumgroupmessage-board
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 11, 2024
Safety Verdict

Is Website Toolbox Forum Safe to Use in 2026?

Generally Safe

Score 99/100

Website Toolbox Forum has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 11, 2024Updated 27d ago
Risk Assessment

The website-toolbox-forums plugin version 2.1.4 exhibits a mixed security posture. On the positive side, the static analysis reveals a lack of immediately exploitable entry points with 0 unprotected AJAX handlers, REST API routes, shortcodes, or cron events. The majority of SQL queries (93%) and output operations (92%) utilize prepared statements and proper escaping, respectively, which are good security practices. The presence of 27 nonce checks and 7 capability checks also suggests an effort towards securing sensitive operations. However, the plugin does have some areas of concern. The taint analysis flagged 2 flows with unsanitized paths, indicating potential risks for path traversal or file manipulation vulnerabilities, even though they are not classified as critical or high severity. The vulnerability history shows a past medium-severity Cross-Site Scripting (XSS) vulnerability, and while there are no currently unpatched CVEs, this history suggests the plugin has had exploitable weaknesses in the past. The single file operation and 13 external HTTP requests, while not inherently insecure, represent potential attack vectors if not handled with extreme care and proper validation. In conclusion, while the plugin has made strides in securing its core functionalities, the presence of unsanitized paths and the past XSS vulnerability warrant careful monitoring and potential updates.

Key Concerns

  • Taint analysis found unsanitized paths
  • History of medium severity CVE (XSS)
  • File operations detected
  • External HTTP requests detected
Vulnerabilities
1

Website Toolbox Forum Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12338medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Website Toolbox Community <= 2.0.1 - Reflected Cross-Site Scripting via websitetoolbox_username

Dec 11, 2024 Patched in 2.0.2 (10d)
Code Analysis
Analyzed Mar 16, 2026

Website Toolbox Forum Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
26 prepared
Unescaped Output
20
223 escaped
Nonce Checks
27
Capability Checks
7
File Operations
1
External Requests
13
Bundled Libraries
0

SQL Query Safety

93% prepared28 total queries

Output Escaping

92% escaped243 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

11 flows2 with unsanitized paths
printLogoutImage (websitetoolbox.php:1255)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Website Toolbox Forum Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 58
actionadmin_noticesadmin\logs.php:415
actionadmin_menuforumHook.php:8
actionadmin_menuforumHook.php:9
actionadmin_initforumHook.php:10
actionadmin_initforumHook.php:11
actionadmin_initforumHook.php:12
actionadmin_initforumHook.php:13
actionwp_headforumHook.php:14
actionwp_headforumHook.php:16
actionadmin_noticesforumHook.php:18
actionadmin_headforumHook.php:19
actionadmin_headforumHook.php:21
actiondelete_userforumHook.php:23
actionwp_loginforumHook.php:25
actionuser_registerforumHook.php:27
actionlogin_headforumHook.php:29
actionwp_logoutforumHook.php:31
actionprofile_updateforumHook.php:33
actionlogin_initforumHook.php:35
actionafter_setup_themeforumHook.php:37
actionenqueue_block_editor_assetsforumHook.php:42
actioninitforumHook.php:47
actioninitforumHook.php:48
actionadmin_initforumHook.php:49
actionadmin_enqueue_scriptsforumHook.php:50
actionpublish_postforumHook.php:51
actionpublish_pageforumHook.php:52
actionrest_after_insert_postforumHook.php:53
actionrest_after_insert_pageforumHook.php:54
actioninitforumHook.php:55
actiontemplate_redirectforumHook.php:56
filterrocket_exclude_defer_jsforumHook.php:58
filterrocket_exclude_jsforumHook.php:63
filterautoptimize_filter_js_excludeforumHook.php:68
filterwpfc_exclude_js_from_minifyforumHook.php:73
actionwp_enqueue_scriptsforumHook.php:81
actionelementor/document/after_saveforumHook.php:85
actiontemplate_redirectforumHook.php:87
actionadmin_initforumHook.php:88
actioninitforumHook.php:89
actionafter_password_resetforumHook.php:90
actionshow_user_profileforumHook.php:91
actionadmin_noticesforumHook.php:92
actionwp_trash_postforumHook.php:94
actionbefore_delete_postforumHook.php:96
actionwp_enqueue_scriptswebsitetoolbox.php:83
actionadmin_enqueue_scriptswebsitetoolbox.php:84
filterlogin_redirectwebsitetoolbox.php:125
filterthe_contentwebsitetoolbox.php:218
filterpage_linkwebsitetoolbox.php:498
filterpost_linkwebsitetoolbox.php:499
filterpage_linkwebsitetoolbox.php:563
filterpost_linkwebsitetoolbox.php:564
filterthe_contentwebsitetoolbox.php:611
filterwp_nav_menu_objectswebsitetoolbox.php:658
filtercomments_templatewebsitetoolbox.php:1410
filterallowed_redirect_hostswebsitetoolbox.php:1412
filterscript_loader_tagwebsitetoolbox.php:1413
Maintenance & Trust

Website Toolbox Forum Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 8, 2026
PHP min version
Downloads64K

Community Trust

Rating92/100
Number of ratings13
Active installs80
Developer Profile

Website Toolbox Forum Developer Profile

Website Toolbox LLC

2 plugins · 90 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Website Toolbox Forum

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/website-toolbox-forums/core/client-info.js
Script Paths
///js/mb/embed.js
Version Parameters
website-toolbox-forums/core/client-info.js?ver=

HTML / DOM Fingerprints

CSS Classes
nocomments
Data Attributes
id="embedded_forum"id="wtEmbedCode"
JS Globals
window.embedded_forum
FAQ

Frequently Asked Questions about Website Toolbox Forum