
WP Subpages Security & Risk Analysis
wordpress.org/plugins/wp-subpagesWP Subpages Widget is a simple plugin to allow for multiple instances to show child pages.
Is WP Subpages Safe to Use in 2026?
Generally Safe
Score 85/100WP Subpages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-subpages plugin v1.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no recorded CVEs, no SQL queries that are not prepared, and no file operations or external HTTP requests, which significantly reduces common attack vectors. The absence of shortcodes, cron events, and REST API routes also limits its direct attack surface within the WordPress environment. However, the code analysis reveals significant concerns, particularly the presence of a dangerous `create_function` call and a complete lack of output escaping. This means that any data processed by the plugin could potentially be rendered insecurely, leading to Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of any nonce or capability checks for its entry points, although currently limited in number, represents a latent risk if the attack surface were to grow or if an attacker could manipulate the plugin's logic.
Key Concerns
- Uses dangerous create_function
- No output escaping
- No nonce checks
- No capability checks
WP Subpages Security Vulnerabilities
WP Subpages Code Analysis
Dangerous Functions Found
Output Escaping
WP Subpages Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Subpages Maintenance & Trust
Maintenance Signals
Community Trust
WP Subpages Alternatives
CC Child Pages
cc-child-pages
Display WordPress child pages in a responsive grid or list using a shortcode, Gutenberg block or Elementor widget.
List Sub Pages
list-sub-pages
This is a WordPress plugin for listing your subpages(childpages) for the current page which is being displayed.
Page Navigator Widget
page-navigator-widget
This plugin is a replacement for the standard Page widget, that works how you want it to do.
WenderHost Subpages Widget
wenderhost-subpages-widget
A widget for displaying a list of subpage links. The list remains consistent regardless of where you are in the hierarchy.
AR Subpages Widget
ar-subpages-widget
Lists subpages of the current parent page
WP Subpages Developer Profile
1 plugin · 10 total installs
How We Detect WP Subpages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
SubpagesWidget<!-- Start CustomMenuLinks Ver<!-- End CustomMenuLinks -->for="SubpagesWidget"id="SubpagesWidget"name="SubpagesWidget"