
Whale-Kit Security & Risk Analysis
wordpress.org/plugins/whale-kitThree alternative to standard widget Categories, Recent Posts and Pages.
Is Whale-Kit Safe to Use in 2026?
Generally Safe
Score 85/100Whale-Kit has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'whale-kit' v2.0 plugin exhibits a strong static security posture with no identified dangerous functions, SQL injection vulnerabilities, or unescaped output. The absence of file operations and external HTTP requests further minimizes potential attack vectors. The plugin also benefits from a clean vulnerability history, with no recorded CVEs, indicating a generally secure development practice. However, the lack of any explicit capability checks or nonce checks on its entry points (shortcodes) is a significant concern. While the attack surface is currently small, any future expansion or introduction of dynamic functionality without these checks could expose the plugin to cross-site request forgery (CSRF) or unauthorized action vulnerabilities. The plugin's current security is good, but relies heavily on the limited nature of its functionality rather than robust security controls.
Key Concerns
- No capability checks on entry points
- No nonce checks on entry points
Whale-Kit Security Vulnerabilities
Whale-Kit Code Analysis
Output Escaping
Whale-Kit Attack Surface
Shortcodes 3
WordPress Hooks 1
Maintenance & Trust
Whale-Kit Maintenance & Trust
Maintenance Signals
Community Trust
Whale-Kit Alternatives
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
SEO Auto Linker
wpa-seo-auto-linker
SEO Auto Linker assists in creating cornerstone SEO content. This is not a full replacement for SEO plugins.
Socius Marketing Page Taxonomy
socius-marketing-page-taxonomy
Adds 2 custom taxonomies (categories & areas served) to Pages for easy, dynamic archive listing.
WP Multilingual Sitemap
wp-multilingual-sitemap
Allows creating complete multilingual sitemaps of your entire blog.
Easy Content Lists
easy-content-lists
Shortcodes for easily listing all your pages, posts, taxonomies, and tags.
Whale-Kit Developer Profile
6 plugins · 630 total installs
How We Detect Whale-Kit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whale-kit/wk-tree.php/wp-content/plugins/whale-kit/wk-terms.php/wp-content/plugins/whale-kit/wk-posts.php