
Widget Display Filter Security & Risk Analysis
wordpress.org/plugins/widget-display-filterSet the display condition for each widget. Widgets display condition setting can be easily, and very easy-to-use plugin.
Is Widget Display Filter Safe to Use in 2026?
Generally Safe
Score 85/100Widget Display Filter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "widget-display-filter" plugin v2.0.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any known CVEs, critical or high-severity taint flows, and a complete lack of file operations or external HTTP requests are strong indicators of good development practices. Furthermore, the presence of numerous nonce checks and a decent number of capability checks on the identified entry points suggests an awareness of common WordPress security vulnerabilities. The fact that all identified entry points (AJAX handlers) are protected is a significant strength.
However, a key area for concern lies within the handling of SQL queries. The analysis reveals one SQL query that is not using prepared statements, which presents a potential risk of SQL injection. Additionally, a low percentage of output escaping (4%) across 23 identified outputs is a significant weakness. While taint analysis did not reveal any unsanitized paths, the lack of robust output escaping means that user-supplied data, if it ever finds its way into these outputs, could potentially lead to Cross-Site Scripting (XSS) vulnerabilities, especially if combined with future changes or undiscovered vulnerabilities.
Overall, the plugin is well-protected against common injection vectors through its input validation and lack of external dependencies. Its vulnerability history being clean is a positive sign. The primary weaknesses are the non-prepared SQL query and the low rate of output escaping, which, despite the current lack of critical taint flows, represent areas that require attention to solidify its security. Addressing these would move the plugin towards a more robust and secure state.
Key Concerns
- SQL query without prepared statement
- Low percentage of properly escaped output
Widget Display Filter Security Vulnerabilities
Widget Display Filter Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Widget Display Filter Attack Surface
AJAX Handlers 3
WordPress Hooks 8
Maintenance & Trust
Widget Display Filter Maintenance & Trust
Maintenance Signals
Community Trust
Widget Display Filter Alternatives
Widget Manager Light
widget-manager-light
Widget Manager lets you control on which pages widgets appear via nice and easy interface. Show or hide widgets. Display relevant content on your page …
Widget Logic Visual
widget-logic-visual
Widget Logic Visual Version lets you control on which pages widgets appear using WP's conditional tags without having to know how conditional tag …
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
AH Display Widgets
ah-display-widgets
Simply hide widgets on specified pages. Adds checkboxes to each widget to either show or hide it on every site page.
Remove Widget Titles
remove-widget-titles
The Remove Widget Titles plugin removes the title from any widget that has a title starting with the "!" character.
Widget Display Filter Developer Profile
12 plugins · 9K total installs
How We Detect Widget Display Filter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widget-display-filter/widget-display-filter.php/wp-content/plugins/widget-display-filter/widget-display-setting.phpwidget-display-filter/widget-display-filter.php?ver=widget-display-filter/widget-display-setting.php?ver=HTML / DOM Fingerprints
wdfilter-settings<!-- widget display filter -->data-wdfilter-idwdfilter_params