
Word Filter Plus Security & Risk Analysis
wordpress.org/plugins/word-filter-plusUpdate or clean the contents of your site, by filtering or replacing words and phrases in your posts, pages, excerpts, titles and comments.
Is Word Filter Plus Safe to Use in 2026?
Generally Safe
Score 85/100Word Filter Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The word-filter-plus v2.0 plugin demonstrates a generally strong security posture based on the provided static analysis. The plugin has a remarkably small attack surface with zero identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) that are unprotected by authentication checks. This is a significant strength as it minimizes the potential for unauthorized access or manipulation. Furthermore, the absence of known CVEs and a clean vulnerability history indicates a history of secure development or diligent patching by the developers.
However, there are areas for improvement. The code analysis reveals that only 57% of output escaping is properly implemented. This means that a notable portion of outputs could potentially be vulnerable to Cross-Site Scripting (XSS) attacks if user-supplied data is not handled carefully before being displayed. While the taint analysis did not reveal any unsanitized paths, the incomplete output escaping represents a potential risk that should be addressed. Additionally, the plugin has 27 SQL queries, and while 85% use prepared statements, the remaining 15% are a potential vector for SQL injection if they handle user input without proper sanitization or prepared statements.
In conclusion, word-filter-plus v2.0 is strong in its minimal attack surface and lack of historical vulnerabilities. The primary weaknesses lie in the inconsistent output escaping and the presence of SQL queries that do not utilize prepared statements. Addressing these specific code-level concerns would further enhance the plugin's security and bring it closer to a best-in-class security profile.
Key Concerns
- Unescaped output detected
- Raw SQL queries without prepared statements
Word Filter Plus Security Vulnerabilities
Word Filter Plus Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Word Filter Plus Attack Surface
WordPress Hooks 14
Maintenance & Trust
Word Filter Plus Maintenance & Trust
Maintenance Signals
Community Trust
Word Filter Plus Alternatives
Filter Everything — Product Filter & WordPress Filter
filter-everything
The most universal filters plugin for WordPress and WooCommerce products.
Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX
ultimate-post
A highly customizable plugin to create news, magazines, and any kind of blog site with post grid, post filter, post slider, and post blocks.
Post Grid
post-grid
Post Grid is a powerful WordPress plugin for creating customizable post grid layouts with advanced query options, allowing users to display posts dyna …
Advanced Post Block – Showcase Posts with Grid, List, Card Layouts and Filters
advanced-post-block
Advanced Post Block lets you add dynamic post grids, lists, sliders, and tickers. Filter content by category, tag, author, or custom post type.
Search and Replace
search-replace
Search and replace content into pages and posts
Word Filter Plus Developer Profile
5 plugins · 3K total installs
How We Detect Word Filter Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/word-filter-plus/js/wfp-settings.js/wp-content/plugins/word-filter-plus/css/wfp-settings.css/wp-content/plugins/word-filter-plus/js/wfp-settings.jsword-filter-plus/js/wfp-settings.js?ver=word-filter-plus/css/wfp-settings.css?ver=HTML / DOM Fingerprints
wfp-settings<!-- Default settings, delete if you want to reset -->data-wfp-settingsWFP_settings