
Widget Entries Security & Risk Analysis
wordpress.org/plugins/widget-entriesWidget Entries plugin creates the Widget post-type in the administration area to make easier the edition of the text widgets, and it also register a n …
Is Widget Entries Safe to Use in 2026?
Generally Safe
Score 85/100Widget Entries has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "widget-entries" plugin v0.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin has no recorded vulnerabilities (CVEs) and no critical findings in taint analysis, suggesting a low likelihood of immediate exploitation. Furthermore, the attack surface is minimal, with only one shortcode and no unprotected entry points like unauthenticated AJAX handlers or REST API routes. However, there are notable areas for improvement. The presence of a single SQL query that is not using prepared statements is a significant concern, as this can lead to SQL injection vulnerabilities if not handled carefully. Additionally, the low percentage of properly escaped output (21%) indicates a high risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly in the browser without proper sanitization. While the vulnerability history is clean, the code quality issues identified in the static analysis present a clear risk that could lead to future vulnerabilities.
Key Concerns
- SQL query not using prepared statements
- Low percentage of properly escaped output
- No capability checks
- No nonce checks
Widget Entries Security Vulnerabilities
Widget Entries Release Timeline
Widget Entries Code Analysis
SQL Query Safety
Output Escaping
Widget Entries Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Widget Entries Maintenance & Trust
Maintenance Signals
Community Trust
Widget Entries Alternatives
LabTheme Companion
labtheme-companion
The plugin generates multiple custom post types and number of exclusive widgets which are needed for wordpress theme developed by labtheme
WooSidebars
woosidebars
WooSidebars adds functionality to display different widgets in a sidebar, according to a context (for example, a specific page or a category).
PHP Code Widget
php-code-widget
Like the Text widget, but also allows working PHP code to be inserted.
Content Aware Sidebars – Fastest Widget Area Plugin
content-aware-sidebars
Display new sidebars on any post, page, category etc. Works with Classic Widgets, Block Widgets, and all themes!
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Widget Entries Developer Profile
1 plugin · 400 total installs
How We Detect Widget Entries
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widget-entries/widget-include-post.phpHTML / DOM Fingerprints
[include-page