
Built-in Widgets Query extend (Custom Post Types & more) Security & Risk Analysis
wordpress.org/plugins/widget-extend-builtin-query[ โ ๐๐๐๐๐๐ ๐๐๐๐๐๐๐ ๐ต๐ ๐ซ๐๐๐๐ ] Plugin extends built-in widgets, so you could add your arguments and query.
Is Built-in Widgets Query extend (Custom Post Types & more) Safe to Use in 2026?
Generally Safe
Score 92/100Built-in Widgets Query extend (Custom Post Types & more) has a strong security track record. Known vulnerabilities have been patched promptly.
The "widget-extend-builtin-query" plugin v1.09 presents a mixed security posture. While it demonstrates some good practices such as a relatively low attack surface and a majority of SQL queries utilizing prepared statements, significant concerns arise from the static analysis. The presence of the `unserialize` function without explicit safeguards is a critical risk, as it can lead to Remote Code Execution if untrusted data is passed to it. Furthermore, the taint analysis reveals a high number of flows with unsanitized paths and one high-severity taint flow, indicating potential vulnerabilities for data manipulation or exposure.
The vulnerability history, specifically a past medium-severity Cross-Site Scripting (XSS) vulnerability, suggests a pattern of potential input validation or output escaping issues within the plugin's codebase. While there are no currently unpatched CVEs, the historical presence of XSS warrants caution. The plugin's limited capability and nonce checks in its attack surface are concerning, especially when combined with the identified potential for unsanitized data flows and the dangerous `unserialize` function. Overall, while the plugin has strengths in its limited attack surface and SQL practices, the identified risks in code analysis and its vulnerability history necessitate careful consideration and potential mitigation.
Key Concerns
- Presence of unserialize() without clear sanitization
- High number of unsanitized taint flows
- 1 high severity taint flow found
- Only 52% of output properly escaped
- Past medium severity XSS vulnerability
- Limited capability checks (2)
Built-in Widgets Query extend (Custom Post Types & more) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Built-in Widgets Query extend <= 1.05 - Reflected Cross-Site Scripting
Built-in Widgets Query extend (Custom Post Types & more) Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Built-in Widgets Query extend (Custom Post Types & more) Attack Surface
WordPress Hooks 37
Maintenance & Trust
Built-in Widgets Query extend (Custom Post Types & more) Maintenance & Trust
Maintenance Signals
Community Trust
Built-in Widgets Query extend (Custom Post Types & more) Alternatives
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Classic Editor +
classic-editor-addon
The "Classic Editor +" plugin disables the block editor, removes enqueued scripts/styles and brings back classic Widgets.
Stratum Widgets for Elementor
stratum
20+ Premium widgets for Elementor, including Advanced Slider, Instagram, Google Maps, Advanced Accordion, Post Grid.
Desert Companion
desert-companion
Desert Companion Enhances Desert Themes with additional functionality.
Livemesh SiteOrigin Widgets
livemesh-siteorigin-widgets
A collection of premium quality widgets for use in any widgetized area or in SiteOrigin page builder. SiteOrigin Widgets Bundle is required.
Built-in Widgets Query extend (Custom Post Types & more) Developer Profile
16 plugins ยท 51K total installs
How We Detect Built-in Widgets Query extend (Custom Post Types & more)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widget-extend-builtin-query/library.php/wp-content/plugins/widget-extend-builtin-query/library_wp.phpHTML / DOM Fingerprints
/wp-json/wp/v2/movies