wp_list_sub_pages Security & Risk Analysis

wordpress.org/plugins/wp-list-sub-pages

wp_list_sub_pages will list only pages within the same category (top-level parent) as the current page.

10 active installs v0.1 PHP + WP 2.0+ Updated Apr 12, 2009
pagepage-treesub_pageswp_list_pages
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is wp_list_sub_pages Safe to Use in 2026?

Generally Safe

Score 85/100

wp_list_sub_pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "wp-list-sub-pages" plugin, in version 0.1, exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, no direct SQL queries, and all output is properly escaped. Furthermore, there are no file operations or external HTTP requests, and importantly, no identifiable attack surface through shortcodes, AJAX, REST API, or cron events. The absence of any recorded vulnerabilities, including CVEs, further reinforces its current secure state.

However, it is crucial to note that the current analysis is based on version 0.1, which is an extremely early release. The complete lack of entry points, nonce checks, and capability checks, while not immediately indicative of a vulnerability in this version, raises a significant concern for future development. As features are added, the absence of these fundamental security mechanisms could lead to severe vulnerabilities if not implemented. The plugin's current safety is largely due to its limited functionality and attack surface, rather than a robust implementation of security best practices for dynamic web applications.

Key Concerns

  • No capability checks implemented
  • No nonce checks implemented
  • No user authentication checks on potential entry points
  • Early version (0.1) lacks robust security implementation
Vulnerabilities
None known

wp_list_sub_pages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

wp_list_sub_pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

wp_list_sub_pages Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

wp_list_sub_pages Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedApr 12, 2009
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

wp_list_sub_pages Developer Profile

Didier Sampaolo

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect wp_list_sub_pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
wp-list-sub-pages/wp_list_sub_pages.php?ver=

HTML / DOM Fingerprints

Shortcode Output
[wp_list_sub_pages
FAQ

Frequently Asked Questions about wp_list_sub_pages