
WPGAlerts Security & Risk Analysis
wordpress.org/plugins/wpgalertsAdd Google Alerts to any WordPress Page or Text Widget with a [WPGAlerts] short code.
Is WPGAlerts Safe to Use in 2026?
Generally Safe
Score 85/100WPGAlerts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpgalerts" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and has a seemingly small attack surface, with no unprotected AJAX handlers or REST API routes identified. It also incorporates nonce and capability checks, along with prepared statements for a portion of its SQL queries, indicating some adherence to good security practices.
However, significant concerns arise from the static code analysis. The most critical issue is that 100% of output is not properly escaped, posing a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis reveals one flow with unsanitized paths, which, while not classified as critical or high in severity by the tool, still represents a potential entry point for malicious input. The presence of SQL queries that do not utilize prepared statements further contributes to the risk of SQL injection vulnerabilities.
Given the absence of past vulnerabilities, the plugin might appear secure, but the current code analysis flags are substantial. The lack of output escaping is a fundamental security flaw that could be exploited regardless of past history. The plugin needs to address its output sanitization and taint flow issues to improve its security. The current state suggests a plugin that has not been thoroughly audited for common web vulnerabilities, particularly output handling.
Key Concerns
- 100% of output is not properly escaped
- Taint flow with unsanitized paths
- SQL queries without prepared statements (55% lack)
WPGAlerts Security Vulnerabilities
WPGAlerts Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPGAlerts Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
WPGAlerts Maintenance & Trust
Maintenance Signals
Community Trust
WPGAlerts Alternatives
XML Sitemap & Google News
xml-sitemap-feed
Take control of your WordPress core XML Sitemap and add a Google News Sitemap.
GN Publisher: Google News Compatible RSS Feeds
gn-publisher
GN Publisher makes RSS feeds that comply with the Google News RSS Feed Technical Requirements for including your site in the Google News.
Dynamic XML Sitemaps Generator for Google
xml-sitemap-generator-for-google
Boost SEO 🚀 with powerful XML, HTML, Image, Video & Google News sitemaps for better search engine indexing.
WP Notification Bars
wp-notification-bars
Create custom notification and alert bar for marketing promotions, alerts, increasing click throughs to other pages and so much more.
Cart Notices for WooCommerce
cart-notices-for-woocommerce
Display on cart page notices based on products and product categories in cart, cart cost, current day and time, customer referrer.
WPGAlerts Developer Profile
1 plugin · 10 total installs
How We Detect WPGAlerts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpgalerts/images/WPGAicon.png