WP Auto Columns Security & Risk Analysis

wordpress.org/plugins/wp-auto-columns

Wrap block of text with shortcode. It will be split into columns. Automagically.

10 active installs v1.0.6 PHP + WP 3.1.0+ Updated Aug 2, 2012
columncolumnslayoutmagazinenewspaper
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Auto Columns Safe to Use in 2026?

Generally Safe

Score 85/100

WP Auto Columns has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The wp-auto-columns plugin, version 1.0.6, exhibits a generally positive security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs, coupled with the plugin's limited attack surface consisting of two shortcodes and no AJAX or REST API endpoints, suggests a low risk of exploitation through common web attack vectors. Furthermore, the analysis indicates good coding practices, with all SQL queries utilizing prepared statements and capability checks implemented for both shortcodes. The presence of a file operation and TinyMCE as a bundled library are noted but do not present immediate security concerns without further context or evidence of malicious use.

However, a significant area of concern is the output escaping, where only 33% of the identified outputs are properly escaped. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data or dynamic content is rendered directly into the page without adequate sanitization. While the taint analysis shows no critical or high-severity flows, this might be due to the limited scope of the analysis or the plugin's specific functionality. The lack of nonce checks, while not immediately alarming given the absence of unprotected AJAX handlers, is a missed opportunity for an additional layer of security, especially for shortcode operations that might involve sensitive actions. Overall, the plugin is relatively secure due to its limited attack surface and lack of known vulnerabilities, but the inadequate output escaping is a tangible risk that should be addressed to prevent potential XSS attacks.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks implemented
Vulnerabilities
None known

WP Auto Columns Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP Auto Columns Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

33% escaped3 total outputs
Attack Surface

WP Auto Columns Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[auto_columns] wp-auto-columns.php:73
[auto-columns] wp-auto-columns.php:74
WordPress Hooks 9
actionadmin_initwp-auto-columns.php:56
actionadmin_menuwp-auto-columns.php:57
filtermce_external_pluginswp-auto-columns.php:64
filtermce_buttonswp-auto-columns.php:65
actioninitwp-auto-columns.php:358
actionadmin_footer-post-new.phpwp-auto-columns.php:360
actionadmin_footer-post.phpwp-auto-columns.php:361
actionadmin_footer-page-new.phpwp-auto-columns.php:362
actionadmin_footer-page.phpwp-auto-columns.php:363
Maintenance & Trust

WP Auto Columns Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedAug 2, 2012
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Auto Columns Developer Profile

Andrey Ovcharov

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Auto Columns

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-auto-columns/css/auto-columns.css
Script Paths
/wp-content/plugins/wp-auto-columns/tinymce/plugins/editor_plugin.js

HTML / DOM Fingerprints

CSS Classes
auto-columns-containercolumns-auto-columns-columncolumn-first-columnlast-columnauto-columns-clear
Shortcode Output
<div class="auto-columns-container<table class="auto-columns-container<div class="auto-columns-column<td class="auto-columns-column
FAQ

Frequently Asked Questions about WP Auto Columns