WP jqtransform archive Security & Risk Analysis

wordpress.org/plugins/wp-jqtransform-archive

Replace the basic Wordpress select archive with the jQuery/jqtransform plugin select.

10 active installs v1.0 PHP + WP 2.7+ Updated Unknown
archivejquerymenu
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WP jqtransform archive Safe to Use in 2026?

Generally Safe

Score 100/100

WP jqtransform archive has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The wp-jqtransform-archive v1.0 plugin exhibits a strong security posture in several key areas. The absence of known CVEs and the fact that all observed SQL queries utilize prepared statements are positive indicators. Furthermore, the plugin demonstrates no file operations or external HTTP requests, which limits potential attack vectors. The static analysis reveals a clean slate regarding dangerous functions, taint flows, and a completely empty attack surface as reported, suggesting a low likelihood of direct code execution or injection vulnerabilities stemming from these components.

However, the analysis does highlight a significant concern regarding output escaping. With only 25% of outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts into the WordPress site through this plugin's output. The complete lack of nonce and capability checks, while not directly tied to an active attack surface in this specific analysis, represents a missed opportunity for robust access control and could become a weakness if new entry points were ever introduced or discovered.

In conclusion, while wp-jqtransform-archive v1.0 benefits from a clean vulnerability history and secure handling of SQL and external interactions, the poor output escaping practices introduce a tangible risk of XSS. The absence of comprehensive security checks like nonces and capability checks should also be noted as potential areas for improvement to ensure a more resilient plugin, especially if its functionality were to expand.

Key Concerns

  • Poor output escaping (25% proper)
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

WP jqtransform archive Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP jqtransform archive Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped8 total outputs
Attack Surface

WP jqtransform archive Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitwp-archive-jqmenu.php:86
actionwp_print_styleswp-archive-jqmenu.php:88
actionplugins_loadedwp-archive-jqmenu.php:90
Maintenance & Trust

WP jqtransform archive Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP jqtransform archive Developer Profile

.fay

5 plugins · 380 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP jqtransform archive

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-jqtransform-archive/jqtransformplugin/jqtransform.min.css/wp-content/plugins/wp-jqtransform-archive/jqtransformplugin/jquery.jqtransform.min.js
Script Paths
/wp-content/plugins/wp-jqtransform-archive/jqtransformplugin/jquery.jqtransform.min.js

HTML / DOM Fingerprints

CSS Classes
jqtransform
Data Attributes
imgPath
JS Globals
jQuery
FAQ

Frequently Asked Questions about WP jqtransform archive