Widgets in Columns Security & Risk Analysis

wordpress.org/plugins/widgets-in-columns

Using this plugin you can show your widgets in desired columns and rows. You can also display an icon beside the widget.

200 active installs v0.2.4 PHP + WP 3.5+ Updated Jul 12, 2014
admincolumnswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Widgets in Columns Safe to Use in 2026?

Generally Safe

Score 85/100

Widgets in Columns has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "widgets-in-columns" plugin v0.2.4 exhibits a strong security posture in several key areas. The absence of known CVEs, a clean vulnerability history, and a lack of identified critical or high-severity issues in taint analysis are positive indicators. Furthermore, the plugin demonstrates good practices by not utilizing dangerous functions, performing all SQL queries with prepared statements, and avoiding file operations and external HTTP requests. However, a significant concern arises from the static analysis, which reveals that 100% of the 13 identified output operations are not properly escaped. This represents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized user input could be directly rendered in the browser. Additionally, the complete lack of nonce and capability checks across all identified entry points, although the entry point count is currently zero, suggests a potential for future vulnerabilities if new entry points are introduced without proper security considerations. The plugin's security is currently reliant on its limited attack surface, but the output escaping issue remains a pressing concern.

Key Concerns

  • All output operations are unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Widgets in Columns Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Widgets in Columns Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped13 total outputs
Attack Surface

Widgets in Columns Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwidgets_initwidgets-in-columns.php:38
actionin_widget_formwidgets-in-columns.php:40
filterwidget_update_callbackwidgets-in-columns.php:41
actionadmin_print_styles-widgets.phpwidgets-in-columns.php:42
filterdynamic_sidebar_paramswidgets-in-columns.php:44
actionwp_enqueue_scriptswidgets-in-columns.php:45
Maintenance & Trust

Widgets in Columns Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedJul 12, 2014
PHP min version
Downloads15K

Community Trust

Rating88/100
Number of ratings8
Active installs200
Developer Profile

Widgets in Columns Developer Profile

shazdeh

24 plugins · 4K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Widgets in Columns

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widgets-in-columns/css/library-rtl.css/wp-content/plugins/widgets-in-columns/css/library.css
Script Paths
/wp-content/plugins/widgets-in-columns/js/admin.js
Version Parameters
widgets-in-columns/js/admin.js?ver=0.2.4

HTML / DOM Fingerprints

CSS Classes
wic-dividerscroller-dividerone-halfone-thirdtwo-thirdone-fourththree-fourthone-fifth+8 more
Data Attributes
wic_widthwic_icon
FAQ

Frequently Asked Questions about Widgets in Columns