Widgets Master Security & Risk Analysis

wordpress.org/plugins/widgets-master

Easily manage the visibility of widgets.

30 active installs v0.2 PHP + WP 3.3+ Updated Dec 7, 2016
categorypageposttaxonomywidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widgets Master Safe to Use in 2026?

Generally Safe

Score 85/100

Widgets Master has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "widgets-master" plugin v0.2 exhibits a concerning security posture, primarily due to a significant lack of output escaping. While the static analysis reveals no direct vulnerabilities such as SQL injection, dangerous functions, or external requests, the fact that 0% of its 32 output operations are properly escaped is a major red flag. This means that any data displayed by the plugin, regardless of its source, is not being neutralized before rendering, leaving it highly susceptible to Cross-Site Scripting (XSS) attacks. The absence of any recorded CVEs and the plugin's small version number might suggest it's either new or has not been widely scrutinized. However, this should not be mistaken for security. The plugin also lacks any evident capability checks, nonce checks, or proper authentication on its (albeit small) entry points, further increasing the risk of unauthorized actions if any vulnerabilities are discovered or introduced.

Key Concerns

  • 0% of outputs properly escaped
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

Widgets Master Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Widgets Master Release Timeline

v0.2Current
v0.1
Code Analysis
Analyzed Mar 17, 2026

Widgets Master Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped32 total outputs
Attack Surface

Widgets Master Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_enqueue_scriptswidgets-master.php:48
actionin_widget_formwidgets-master.php:49
filterwidget_display_callbackwidgets-master.php:50
filterwidget_update_callbackwidgets-master.php:51
Maintenance & Trust

Widgets Master Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedDec 7, 2016
PHP min version
Downloads3K

Community Trust

Rating74/100
Number of ratings6
Active installs30
Developer Profile

Widgets Master Developer Profile

jvwissen

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Widgets Master

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widgets-master/css/widgets-master.css/wp-content/plugins/widgets-master/js/widgets-master.js
Script Paths
/wp-content/plugins/widgets-master/js/widgets-master.js
Version Parameters
widgets-master/css/widgets-master.css?ver=widgets-master/js/widgets-master.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="widgets-master-home"name="widgets-master-archive"name="widgets-master-404"name="widgets-master-search"name="widgets-master-single"name="posttype[]"+2 more
FAQ

Frequently Asked Questions about Widgets Master