Widon't Part Deux Security & Risk Analysis

wordpress.org/plugins/widont-part-deux

Widon't Part Deux eliminates typographic widows in the titles and content your posts and pages.

70 active installs v1.3.1 PHP + WP 3.5+ Updated Sep 2, 2014
orphanstitletypographywidows
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widon't Part Deux Safe to Use in 2026?

Generally Safe

Score 85/100

Widon't Part Deux has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "widont-part-deux" v1.3.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate robust security practices, with no dangerous functions used, all SQL queries employing prepared statements, and all output properly escaped. The lack of file operations and external HTTP requests further reinforces this positive assessment.

The taint analysis shows no identified flows with unsanitized paths, indicating that data is not being mishandled in a way that could lead to vulnerabilities. The vulnerability history is also clean, with zero known CVEs, unpatched vulnerabilities, or recorded common vulnerability types. This suggests a well-maintained and secure plugin.

While the plugin demonstrates excellent adherence to secure coding practices, the complete absence of capability checks and nonce checks in any entry points, although currently not exposed due to the minimal attack surface, represents a potential area for future concern. If the plugin were to introduce new features with user-facing interactions, the lack of these fundamental security checks could become a significant risk. However, based solely on the provided data for v1.3.1, the plugin appears to be highly secure.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Widon't Part Deux Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Widon't Part Deux Release Timeline

v1.3.1Current
v1.3.0
v1.2.0
v1.1.1
Code Analysis
Analyzed Mar 16, 2026

Widon't Part Deux Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Widon't Part Deux Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initwp-widont.php:44
actionadmin_menuwp-widont.php:45
filterthe_titlewp-widont.php:49
filterthe_contentwp-widont.php:50
Maintenance & Trust

Widon't Part Deux Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 2, 2014
PHP min version
Downloads3K

Community Trust

Rating96/100
Number of ratings5
Active installs70
Developer Profile

Widon't Part Deux Developer Profile

Morgan Estes

7 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Widon't Part Deux

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
widont_deux[tags]
FAQ

Frequently Asked Questions about Widon't Part Deux