WPkmkz Bootstrap Grid Widgets Security & Risk Analysis

wordpress.org/plugins/wpkmkz-boostrap-grid-widgets

Adds a menu on the bottom of wp widgets where you can set bootstrap columns or rows

10 active installs v1.0.2 PHP + WP 3.6+ Updated Apr 15, 2014
bootstrapwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPkmkz Bootstrap Grid Widgets Safe to Use in 2026?

Generally Safe

Score 85/100

WPkmkz Bootstrap Grid Widgets has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "wpkmkz-bootstrap-grid-widgets" v1.0.2 plugin exhibits a strong security posture based on the provided static analysis. There are no identified attack vectors such as AJAX handlers, REST API routes, shortcodes, or cron events, indicating a minimal attack surface. The absence of dangerous functions, file operations, and external HTTP requests further reinforces this positive assessment. Furthermore, all SQL queries are properly prepared, and there are no reported vulnerabilities or CVEs associated with this plugin. This suggests a commitment to secure coding practices by the developers.

However, a significant concern is the low percentage of properly escaped output (5%). With 40 total outputs analyzed, this means a substantial number of outputs are not being adequately sanitized before being displayed to users. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly handled. Additionally, the complete lack of nonce checks and capability checks on any potential entry points, though currently non-existent, indicates a potential weakness if new functionalities that handle sensitive data or user actions are introduced in the future without proper security measures. The plugin's vulnerability history being clean is a positive indicator, but the output escaping issue warrants attention.

Key Concerns

  • Low output escaping percentage
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

WPkmkz Bootstrap Grid Widgets Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPkmkz Bootstrap Grid Widgets Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped40 total outputs
Attack Surface

WPkmkz Bootstrap Grid Widgets Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionin_widget_formwpkmkz-bootstrap-grid-widgets.php:162
filterwidget_update_callbackwpkmkz-bootstrap-grid-widgets.php:185
filterdynamic_sidebar_paramswpkmkz-bootstrap-grid-widgets.php:233
actionadmin_headwpkmkz-bootstrap-grid-widgets.php:260
Maintenance & Trust

WPkmkz Bootstrap Grid Widgets Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedApr 15, 2014
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

WPkmkz Bootstrap Grid Widgets Developer Profile

skapator

5 plugins · 3K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPkmkz Bootstrap Grid Widgets

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wpkmkz-bs-grid-widgetswpkmkz-bs-grid-widgets-handlewpkmkz-bs-grid-widgets-innerwpkmkz-bs-grid-input
Data Attributes
data-wpkmkz_bs_row_startdata-wpkmkz_bs_row_enddata-wpkmkz_bs_col_lgdata-wpkmkz_bs_col_mddata-wpkmkz_bs_col_smdata-wpkmkz_bs_col_xs+4 more
FAQ

Frequently Asked Questions about WPkmkz Bootstrap Grid Widgets