
WP-Paginate Security & Risk Analysis
wordpress.org/plugins/wp-paginateWP-Paginate is a simple and flexible pagination plugin which provides users with better navigation on your WordPress site.
Is WP-Paginate Safe to Use in 2026?
Generally Safe
Score 91/100WP-Paginate has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wp-paginate plugin, version 2.2.4, demonstrates a generally good security posture, with strong adherence to secure coding practices such as the use of prepared statements for all SQL queries, robust nonce checks on its AJAX handlers, and a high percentage of properly escaped output. The absence of any detected taint flows, critical or high severity vulnerabilities, or external HTTP requests further contributes to its positive security profile. However, the plugin's history reveals two known medium-severity Cross-Site Scripting (XSS) vulnerabilities, with the last one being patched in mid-2022. While no unpatched vulnerabilities are currently listed, this history suggests a potential for XSS issues if input sanitization is not rigorously maintained in future development.
The static analysis indicates a relatively small attack surface limited to four AJAX handlers, all of which appear to have proper authentication checks. The absence of REST API routes and shortcodes also reduces potential entry points. Despite the positive indicators, the past XSS vulnerabilities warrant vigilance. The plugin's strengths lie in its technical implementation of security measures, but its vulnerability history is a reminder that even well-coded plugins can be susceptible to input-related vulnerabilities if not actively maintained and tested against evolving threat vectors.
Key Concerns
- Medium severity XSS vulnerabilities in history
- Older patch date for last vulnerability (2022-06-16)
WP-Paginate Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP-Paginate <= 2.1.8 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Paginate <= 2.1.3 - Admin+ Stored Cross-Site Scripting
WP-Paginate Release Timeline
WP-Paginate Code Analysis
Output Escaping
WP-Paginate Attack Surface
AJAX Handlers 4
WordPress Hooks 11
Maintenance & Trust
WP-Paginate Maintenance & Trust
Maintenance Signals
Community Trust
WP-Paginate Alternatives
TW Pagination
tw-pagination
TW Pagination is a simple and flexible pagination plugin which provides users with better navigation on your WordPress site.
WP-SEO-Paginate
wp-seo-paginate
Provides users with better and simple navigation interface.
Module Pager
module-pager
Management tools for any custom pagination.
WP-PageNavi
wp-pagenavi
Adds a more advanced paging navigation interface.
WP PageNavi Style
wp-pagenavi-style
Adds a more styling options to Wp-PageNavi wordpress plugin.
WP-Paginate Developer Profile
5 plugins · 103K total installs
How We Detect WP-Paginate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-paginate/css/admin.css/wp-content/plugins/wp-paginate/css/wpp-paginate.css/wp-content/plugins/wp-paginate/js/wpp-paginate.js/wp-content/plugins/wp-paginate/js/wpp-paginate.jswp-paginate/css/wpp-paginate.css?ver=wp-paginate/js/wpp-paginate.js?ver=HTML / DOM Fingerprints
wpp-pagination<!-- WP-Paginate --><!-- WP-Paginate End -->data-wpp-noncedata-wpp-ajax-urldata-wpp-iddata-wpp-typewpp_paginate[wp_paginate]