
WP-CMS Security & Risk Analysis
wordpress.org/plugins/wp-cmsWP-CMS is a plugin for Wordpress that changes the functionality of the Wordpress admin backend to act more like a CMS.
Is WP-CMS Safe to Use in 2026?
Generally Safe
Score 85/100WP-CMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-cms" v2.1 plugin exhibits a concerning lack of security best practices, despite its seemingly small attack surface and zero recorded CVEs. The static analysis reveals significant vulnerabilities in how the plugin handles data. All 6 SQL queries are unparameterized, posing a high risk of SQL injection. Furthermore, none of the 3 output operations are properly escaped, creating a strong possibility of cross-site scripting (XSS) vulnerabilities. The taint analysis also flagged 2 flows with unsanitized paths, which, while not classified as critical or high severity in this report, directly correlate with the observed lack of escaping and could lead to serious security breaches if exploited.
The absence of any identified CVEs or past vulnerabilities might suggest a recent or less targeted plugin. However, the internal code quality issues are a significant red flag. The complete lack of capability checks, nonce checks, and proper output escaping on all analyzed entry points (even if the attack surface is currently zero) means that any future expansion or modification of the plugin could introduce critical vulnerabilities. The plugin's current state does not demonstrate robust security architecture, and the identified flaws require immediate attention to prevent potential compromise.
Key Concerns
- All SQL queries use prepared statements
- No output operations are properly escaped
- Taint flows with unsanitized paths found
- No capability checks
- No nonce checks
WP-CMS Security Vulnerabilities
WP-CMS Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-CMS Attack Surface
WordPress Hooks 3
Maintenance & Trust
WP-CMS Maintenance & Trust
Maintenance Signals
Community Trust
WP-CMS Alternatives
More Types
more-types
Adds any number of extra Post types, besides Post and Page, for the WordPess Admin. Also allows for special editing rights for specific User roles for …
CMS Dashboard
content-management-system-dashboard
Improve the usability of your Wordpress CMS system. This plug-in creates a dashboard widget with clearly labeled large buttons of the most common task …
Lock Pages
lock-pages
Lock Pages prevents specified pages (or all pages), posts, or custom post types from having their slug, parent, status or password edited, or from bei …
Pagely MultiEdit
pagely-multiedit
MultiEdit adds tinyMCE editable "blocks" to WordPress custom page templates.
Multiple Content Types
multiple-content-types
Easily select which content types (custom post types) you want to display on your main blog and archive pages.
WP-CMS Developer Profile
6 plugins · 260 total installs
How We Detect WP-CMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-cms/wp-cms.css/wp-content/plugins/wp-cms/wp-cms.js/wp-content/plugins/wp-cms/wp-cms.jswp-cms/wp-cms.css?ver=wp-cms/wp-cms.js?ver=HTML / DOM Fingerprints
wp-cms-settingswindow.location