
WP-Archives Security & Risk Analysis
wordpress.org/plugins/wp-archivesDisplay your archives with year/month list.
Is WP-Archives Safe to Use in 2026?
Generally Safe
Score 85/100WP-Archives has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-archives" plugin version 0.8 exhibits a generally strong security posture, with no reported vulnerabilities or critical findings in static and taint analysis. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and file operations significantly limits the attack surface. Furthermore, the code signals indicate a lack of dangerous functions and external HTTP requests, which are common vectors for exploits. However, there are significant concerns regarding database interaction and output handling. The presence of two SQL queries that do not utilize prepared statements, coupled with zero instances of proper output escaping, presents a notable risk. This could potentially lead to SQL injection vulnerabilities if user-supplied data is not meticulously sanitized before being used in database queries, or Cross-Site Scripting (XSS) vulnerabilities if output is not properly escaped before being displayed to users. While the plugin has no known vulnerability history, the identified coding practices in SQL and output handling warrant attention to prevent future security issues. The plugin's strength lies in its limited attack surface and lack of historically exploited patterns, but the implementation of its core functionalities, particularly database and output handling, needs improvement to ensure robust security.
Key Concerns
- SQL queries not using prepared statements
- Output not properly escaped
WP-Archives Security Vulnerabilities
WP-Archives Code Analysis
SQL Query Safety
Output Escaping
WP-Archives Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP-Archives Maintenance & Trust
Maintenance Signals
Community Trust
WP-Archives Alternatives
Smart Archives Reloaded
smart-archives-reloaded
Easily display posts grouped by year and month, in one or more elegant formats
Widget Pack
ts-widget-pack
Widget Pack is a WordPress plugin that enables essential, yet powerful features for your website.
A-Z Indexing startup
a-z-indexing-startup
This is a simple plugin that provides an A-Z index of the posts displayed on a particular page based on the post title.
List Posts Alphabetically
list-posts-alphabetically
Lists posts alphabetically by category.
Binge Reading Archive Page
all-posts-archive-page
A plugin to create an "all posts since this site started by month" listing. Works on all themes with a shortcode.
WP-Archives Developer Profile
4 plugins · 2K total installs
How We Detect WP-Archives
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<!-- WP-Archives 0.8 by unijimpe --><!--wp_archives--><strong><ul><li></a>