
WenderHost Subpages Widget Security & Risk Analysis
wordpress.org/plugins/wenderhost-subpages-widgetA widget for displaying a list of subpage links. The list remains consistent regardless of where you are in the hierarchy.
Is WenderHost Subpages Widget Safe to Use in 2026?
Generally Safe
Score 85/100WenderHost Subpages Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wenderhost-subpages-widget" v1.5.3 plugin exhibits a mixed security posture. On the positive side, the plugin has a minimal attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries utilize prepared statements, indicating good practices in these areas. Furthermore, there is no recorded vulnerability history, suggesting a generally stable and secure past. However, the static analysis reveals significant concerns. The presence of the `create_function` dangerous function is a red flag, as it can lead to code injection vulnerabilities if not handled with extreme care. More critically, 100% of output is not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities across all its output points. The lack of nonce and capability checks on the limited entry points, although currently zero, means that if any were introduced in the future, they would likely be unprotected, increasing the risk of unauthorized actions or information disclosure.
Key Concerns
- Dangerous function used (create_function)
- 100% of output is not properly escaped
- No nonce checks
- No capability checks
WenderHost Subpages Widget Security Vulnerabilities
WenderHost Subpages Widget Code Analysis
Dangerous Functions Found
Output Escaping
WenderHost Subpages Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
WenderHost Subpages Widget Maintenance & Trust
Maintenance Signals
Community Trust
WenderHost Subpages Widget Alternatives
List Sub Pages
list-sub-pages
This is a WordPress plugin for listing your subpages(childpages) for the current page which is being displayed.
Subpage Listing
subpage-listing
Allows you to display a list of the child pages of the currently viewed page.
GD Pages Navigator
gd-pages-navigator
Simple and powerful widget plugin to create enhanced navigation for hierarchical post types, based on different criteria for filtering and display of …
Page Navigator Widget
page-navigator-widget
This plugin is a replacement for the standard Page widget, that works how you want it to do.
AR Subpages Widget
ar-subpages-widget
Lists subpages of the current parent page
WenderHost Subpages Widget Developer Profile
2 plugins · 200 total installs
How We Detect WenderHost Subpages Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_wenderhost-subpagesid="widget_wenderhost-subpages-title"name="widget_wenderhost-subpages-title"id="widget_wenderhost-subpages-hide_title"name="widget_wenderhost-subpages-hide_title"id="widget_wenderhost-subpages-sort"name="widget_wenderhost-subpages-sort"+2 more