
WP Page Tree Security & Risk Analysis
wordpress.org/plugins/wp-page-treeWidget to display a navigable tree of pages.
Is WP Page Tree Safe to Use in 2026?
Generally Safe
Score 85/100WP Page Tree has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-page-tree" v1.1.1 plugin exhibits a strong security posture in several key areas. The static analysis reveals no identified attack surface points, meaning there are no apparent AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited. Furthermore, the code signals show a complete absence of dangerous functions, file operations, and external HTTP requests. The lack of any recorded vulnerabilities, including CVEs, in its history is a significant positive indicator of past security diligence.
However, there are areas that warrant caution. The plugin uses one SQL query but does not utilize prepared statements, introducing a potential risk of SQL injection if the query's inputs are not rigorously validated and sanitized. Additionally, only 22% of output escaping is properly handled, which could lead to cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on any potential entry points (even though none are explicitly identified) means that if an entry point were to be discovered or introduced in a future update, it might lack fundamental security protections.
In conclusion, while the plugin's current known attack surface and vulnerability history are excellent, the lack of prepared statements for its SQL query and the low percentage of proper output escaping represent significant, albeit fixable, security concerns. The absence of fundamental security checks like nonces and capability checks, even without a direct attack surface, suggests a potential for future vulnerabilities if the plugin's functionality expands.
Key Concerns
- SQL query not using prepared statements
- Low percentage of output escaping
- No nonce checks
- No capability checks
WP Page Tree Security Vulnerabilities
WP Page Tree Release Timeline
WP Page Tree Code Analysis
SQL Query Safety
Output Escaping
WP Page Tree Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Page Tree Maintenance & Trust
Maintenance Signals
Community Trust
WP Page Tree Alternatives
Nested Pages
wp-nested-pages
Nested Pages provides a drag and drop interface for managing pages & posts in the WordPress admin, while maintaining quick edit functionality.
Admin Menu Tree Page View
admin-menu-tree-page-view
Get a tree view of all your pages directly in the admin menu. Search, add, edit, view, re-order – all is just one click away!
Menu By User Roles
menu-by-user-roles
Menu By User Roles allows you to control the visibility of menu items based on user roles.
Widget Pack
ts-widget-pack
Widget Pack is a WordPress plugin that enables essential, yet powerful features for your website.
PageMagic – Page Lists
pagemagic-page-lists
Create visual hierarchies of site pages. Options to list all pages, subpages, current page siblings. Also able to show page featured image and custom …
WP Page Tree Developer Profile
8 plugins · 76K total installs
How We Detect WP Page Tree
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-page-tree/style.css/wp-content/plugins/wp-page-tree/icons/folderopen.gif/wp-content/plugins/wp-page-tree/icons/empty.gif/wp-content/plugins/wp-page-tree/icons/line.gif/wp-content/plugins/wp-page-tree/icons/minus.gif/wp-content/plugins/wp-page-tree/icons/minusbottom.gif/wp-content/plugins/wp-page-tree/icons/plus.gif/wp-content/plugins/wp-page-tree/icons/plusbottom.gif+7 morewp-page-tree/style.css?ver=HTML / DOM Fingerprints
wppt_minuswppt_plustitleid="wppt"id="wppt"class="title"id="wppt"class="wppt_minus"class="wppt_plus"+1 more<div id="wppt">
<div style="height: 16px"><img src="