
WP Subdomains (Revisited) Security & Risk Analysis
wordpress.org/plugins/wp-subdomains-revisitedSetup your main categories, pages, and authors as subdomains with custom themes. Surely will come for more options...
Is WP Subdomains (Revisited) Safe to Use in 2026?
Generally Safe
Score 85/100WP Subdomains (Revisited) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wp-subdomains-revisited" v0.9.3 presents a generally positive security posture, particularly due to its minimal attack surface and lack of known historical vulnerabilities. The static analysis reveals no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the plugin's exposure to common attack vectors. Furthermore, the absence of dangerous function usage and file operations is a strong indicator of good coding practices.
However, there are areas for concern within the code itself. A significant portion of SQL queries (83%) are not using prepared statements, which could lead to SQL injection vulnerabilities if user input is not properly sanitized before being incorporated into these queries. The complete lack of proper output escaping (0%) is a critical weakness, exposing the plugin to potential Cross-Site Scripting (XSS) vulnerabilities. While only two taint flows were analyzed, the absence of critical or high severity issues in this specific analysis is a positive sign, but it does not negate the risks posed by unescaped output and raw SQL queries.
The plugin's vulnerability history being entirely clean, with no recorded CVEs or past vulnerabilities, suggests a history of secure development or at least a lack of publicly disclosed issues. This, combined with the presence of nonce and capability checks, builds some confidence. Nevertheless, the identified weaknesses in SQL query preparation and especially output escaping warrant attention to prevent potential security incidents.
Key Concerns
- Raw SQL queries without prepared statements
- No output escaping
WP Subdomains (Revisited) Security Vulnerabilities
WP Subdomains (Revisited) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Subdomains (Revisited) Attack Surface
WordPress Hooks 42
Maintenance & Trust
WP Subdomains (Revisited) Maintenance & Trust
Maintenance Signals
Community Trust
WP Subdomains (Revisited) Alternatives
WP Super Subdomains
wp-super-subdomains
This plugin allow you create subdomain without using Wordpress Multisite ! Setup your main categories, tag, pages, and authors as subdomains !
List category posts
list-category-posts
Very customizable plugin to list posts by category (or tag, author and more) in a post, page or widget. Uses the [catlist] shortcode to select posts.
Category Posts Widget
category-posts
Adds a widget that shows the most recent posts from a single category.
Essential Widgets
essential-widgets
Essential Widgets is a WordPress plugin for widgets that allows you to create and add amazing widgets with high customization option
Flexible Posts Widget
flexible-posts-widget
An advanced posts display widget with many options. Display posts in your sidebars any way you'd like!
WP Subdomains (Revisited) Developer Profile
2 plugins · 40 total installs
How We Detect WP Subdomains (Revisited)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-subdomains-revisited/plugin/admin.css/wp-content/plugins/wp-subdomains-revisited/plugin/admin.js/wp-content/plugins/wp-subdomains-revisited/plugin/admin.jswp-subdomains-revisited/plugin/admin.css?ver=wp-subdomains-revisited/plugin/admin.js?ver=HTML / DOM Fingerprints
wps-admin-settingsdata-wps-idwps_admin