
WP-PageNavi Security & Risk Analysis
wordpress.org/plugins/wp-pagenaviAdds a more advanced paging navigation interface.
Is WP-PageNavi Safe to Use in 2026?
Generally Safe
Score 92/100WP-PageNavi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-pagenavi plugin v2.94.5 demonstrates a relatively strong security posture in terms of its attack surface and known vulnerability history. It reports zero AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected, indicating a well-defined and contained entry point. The absence of any recorded CVEs, either historical or current, is a significant positive indicator of its stability and security over time. However, the static analysis reveals some concerning code-level practices that offset these strengths.
The primary concern stems from the database interactions. All four identified SQL queries are executed without prepared statements, which presents a significant risk of SQL injection vulnerabilities if any of the input feeding these queries is not meticulously sanitized. Furthermore, the taint analysis highlights four flows with unsanitized paths, all classified as high severity. This, combined with the raw SQL queries, strongly suggests that these unsanitized inputs are being directly incorporated into SQL statements.
While the plugin includes nonce checks and a reasonable percentage of output escaping, the critical findings in the taint analysis and the complete lack of prepared statements for SQL queries are major weaknesses. The vulnerability history is reassuring, but it doesn't negate the immediate risks identified in the code. In conclusion, the plugin's lack of exposed entry points and historical CVEs are strengths, but the presence of high-severity taint flows and raw SQL queries creates a substantial risk that requires immediate attention.
Key Concerns
- High severity taint flows found
- SQL queries without prepared statements
- Low output escaping percentage (49%)
WP-PageNavi Security Vulnerabilities
WP-PageNavi Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-PageNavi Attack Surface
WordPress Hooks 13
Maintenance & Trust
WP-PageNavi Maintenance & Trust
Maintenance Signals
Community Trust
WP-PageNavi Alternatives
WP PageNavi Style
wp-pagenavi-style
Adds a more styling options to Wp-PageNavi wordpress plugin.
Simplistic page navi
simplistic-page-navi
This plugin displays a linked list by page number. It is simple but has several features.
WP-SEO-Paginate
wp-seo-paginate
Provides users with better and simple navigation interface.
Pagination by BestWebSoft – Customizable WordPress Content Splitter and Navigation Plugin
pagination
Add customizable WordPress pagination to your website. Easily split long posts and pages into multiple parts for improved navigation and user experien …
Back and Forward Button
back-and-forward-button
Add ◄ and ► button anywhere in website matching theme color and style. Check the Live Preview first, then Install.
WP-PageNavi Developer Profile
20 plugins · 889K total installs
How We Detect WP-PageNavi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-pagenavi/style.csswp-pagenavi/style.css?ver=HTML / DOM Fingerprints
wp-pagenavipagesfirstpreviouspostslinkextendsmallerpagecurrent+3 morearia-label="First Page"aria-label="Previous Page"aria-label="Next Page"aria-label="Last Page"aria-current="page"<div class="wp-pagenavi">