
WP-SNAP EXT! Security & Risk Analysis
wordpress.org/plugins/wp-snap-extendedALPHABETICAL PAGING creates an user interface for navigating alphabetically on post titles.
Is WP-SNAP EXT! Safe to Use in 2026?
Generally Safe
Score 85/100WP-SNAP EXT! has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-snap-extended" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events, along with zero reported vulnerabilities, suggests a minimal attack surface and a history of secure development. The code also demonstrates good practices by utilizing prepared statements for its single SQL query and incorporating a nonce check and capability check, indicating an awareness of common WordPress security vulnerabilities. The taint analysis revealing no unsanitized paths is also a very positive sign.
However, a significant concern arises from the output escaping analysis, which shows that 100% of the 11 identified outputs are not properly escaped. This creates a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. If any of the data processed by the plugin is user-controlled and then displayed without proper sanitization, an attacker could inject malicious scripts into the user's browser. Despite the lack of historical vulnerabilities and a small attack surface, this unescaped output is a critical weakness that needs immediate attention.
In conclusion, while the plugin has a clean record and a small attack surface with some good security practices in place, the complete lack of output escaping for all identified outputs is a major security flaw. This flaw significantly outweighs the positive aspects and demands remediation. The plugin is strong in preventing common entry point vulnerabilities and SQL injection, but critically weak in protecting against XSS.
Key Concerns
- All outputs lack proper escaping
WP-SNAP EXT! Security Vulnerabilities
WP-SNAP EXT! Release Timeline
WP-SNAP EXT! Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-SNAP EXT! Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP-SNAP EXT! Maintenance & Trust
Maintenance Signals
Community Trust
WP-SNAP EXT! Alternatives
WP-SNAP!
wp-snap
WP-SNAP! (WordPress System for Navigating Alphabetized Posts) creates an user interface for navigating alphabetized post titles.
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
WP-PageNavi
wp-pagenavi
Adds a more advanced paging navigation interface.
Max Mega Menu
megamenu
An easy to use mega menu plugin. Written the WordPress way.
LuckyWP Table of Contents
luckywp-table-of-contents
Creates SEO-friendly table of contents for your posts/pages. Works automatically or manually (via shortcode, Gutenberg block or widget).
WP-SNAP EXT! Developer Profile
3 plugins · 60 total installs
How We Detect WP-SNAP EXT!
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-snap-extended/snap-style.csswp-snap-extended/snap-style.css?ver=HTML / DOM Fingerprints
snap_navsnap_selected-------------------------------------------------------------------------------All the Credit goes to Nathan Olsen. Who was the original author of this plugin.We tweak it and make it compatilbe with the higher version of wordpress with coding adjustment+14 morekey_snap_menukey_snap_menumisckey_snap_recentkey_snap_csscls1key_snap_csscls2key_snap_exclude+13 more