
WP LIST PAGES BY CUSTOM TAXONOMY Security & Risk Analysis
wordpress.org/plugins/wp-list-pages-by-custom-taxonomyWidget to lists posts of any active post-type, filtering by any term of any active custom taxonomy. display title, or thumb, date and excerpt too.
Is WP LIST PAGES BY CUSTOM TAXONOMY Safe to Use in 2026?
Generally Safe
Score 85/100WP LIST PAGES BY CUSTOM TAXONOMY has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-list-pages-by-custom-taxonomy" plugin v1.4.10 exhibits a generally positive security posture, with no known vulnerabilities (CVEs) or critical issues identified through taint analysis. The static analysis shows a clean slate regarding dangerous functions, raw SQL queries, and external HTTP requests, all indicating a commitment to secure coding practices.
However, there are areas for concern. A significant portion of output (76%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without sanitization. The absence of nonce checks and capability checks on all entry points (though the analysis reports zero entry points, this often means they are not properly registered or detected, and still represent a potential gap if functionality exists) is a notable weakness. While the attack surface appears minimal based on the provided metrics, the lack of robust input validation and authorization mechanisms remains a risk.
The absence of any recorded vulnerabilities in its history is a strong positive indicator. It suggests that past security reviews or community scrutiny have not uncovered significant flaws. However, this should not lead to complacency. The plugin's current strengths lie in its clean code regarding direct database manipulation and external interactions. The primary weakness lies in the potential for XSS due to insufficient output escaping, and the lack of comprehensive security checks on its (currently undetected) entry points.
Key Concerns
- High percentage of unescaped output
- Missing nonce checks on entry points
- Missing capability checks on entry points
WP LIST PAGES BY CUSTOM TAXONOMY Security Vulnerabilities
WP LIST PAGES BY CUSTOM TAXONOMY Code Analysis
SQL Query Safety
Output Escaping
WP LIST PAGES BY CUSTOM TAXONOMY Attack Surface
WordPress Hooks 9
Maintenance & Trust
WP LIST PAGES BY CUSTOM TAXONOMY Maintenance & Trust
Maintenance Signals
Community Trust
WP LIST PAGES BY CUSTOM TAXONOMY Alternatives
Custom Post Type Widgets
custom-post-type-widgets
Custom Post Type Widgets plugin adds default custom post type widgets.
Ultimate Posts Widget
ultimate-posts-widget
The ultimate widget for displaying posts, custom post types or sticky posts with an array of options.
NS Category Widget
ns-category-widget
A plugin to add widget for listing Categories and Taxonomies. Extending Default WordPress Category Widget.
Listings Post Type Enable
listings-post-type-enable
A simple plugin that creates a "listings" custom post type. It is also add a recent listings custom widget and a new category listings widge …
Super recent posts
super-recent-posts
Widget that can display recent posts from multiple categories, taxonomies, terms custom post types.
WP LIST PAGES BY CUSTOM TAXONOMY Developer Profile
1 plugin · 100 total installs
How We Detect WP LIST PAGES BY CUSTOM TAXONOMY
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-list-pages-by-custom-taxonomy/css/style.css/wp-content/plugins/wp-list-pages-by-custom-taxonomy/js/pbytax_admin_notices.js/wp-content/plugins/wp-list-pages-by-custom-taxonomy/js/pbytax_admin_notices.jswp-list-pages-by-custom-taxonomy/style.css?ver=js/pbytax_admin_notices.js?ver=HTML / DOM Fingerprints
<!-- START WIDGET WP_LIST_PAGES_BY_CUSTOM_TAXONOMY --><!-- END WIDGET WP_LIST_PAGES_BY_CUSTOM_TAXONOMY -->data-pbytax-widget-iddata-pbytax-posttypedata-pbytax-taxonomydata-pbytax-termsdata-pbytax-orderbydata-pbytax-order+14 morewindow.pbytax_admin_notices_cookie_namewindow.pbytax_admin_notices_hide_url[wp_list_pages_by_custom_taxonomy]