
WordsTree Pocket Navigator Security & Risk Analysis
wordpress.org/plugins/wt-pocket-navigatorThe plugin to make available for you, while you write, your Pocket favorites.
Is WordsTree Pocket Navigator Safe to Use in 2026?
Generally Safe
Score 85/100WordsTree Pocket Navigator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wt-pocket-navigator" plugin v1.0.2 exhibits a concerning security posture primarily due to its unprotected AJAX handlers. While the plugin shows positive signs like the absence of dangerous functions and the exclusive use of prepared statements for SQL queries, the two AJAX entry points lack any authentication or capability checks. This represents a significant attack surface that could be exploited by unauthenticated users.
Furthermore, the taint analysis indicates that all analyzed flows involve unsanitized paths, although thankfully, these did not escalate to critical or high severity issues. The low percentage of properly escaped output (25%) is another area of concern, suggesting potential for cross-site scripting (XSS) vulnerabilities, especially when combined with the unprotected AJAX handlers. The plugin's vulnerability history is clean, which is a positive indicator of past security diligence. However, the current static analysis reveals fundamental security weaknesses that need immediate attention.
In conclusion, while the plugin benefits from a lack of historical vulnerabilities and safe SQL practices, the presence of unprotected AJAX handlers and unsanitized taint flows are critical flaws. The poorly escaped output further exacerbates these risks. Addressing these immediate vulnerabilities is crucial to improving the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
WordsTree Pocket Navigator Security Vulnerabilities
WordsTree Pocket Navigator Release Timeline
WordsTree Pocket Navigator Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
WordsTree Pocket Navigator Attack Surface
AJAX Handlers 2
WordPress Hooks 12
Maintenance & Trust
WordsTree Pocket Navigator Maintenance & Trust
Maintenance Signals
Community Trust
WordsTree Pocket Navigator Alternatives
Ocean Extra
ocean-extra
The ultimate companion for OceanWP. Adds local Google Fonts, mega menus, site templates, and per-page settings for total design authority.
Stratum Widgets for Elementor
stratum
20+ Premium widgets for Elementor, including Advanced Slider, Instagram, Google Maps, Advanced Accordion, Post Grid.
Recent Posts Plus
recent-posts-plus
An advanced version of the WordPress Recent Posts widget, allows display of thumbnails, post excerpt, author, comment count, and more.
Simple Social Icon Widget
simple-social-icon-widget
License GPLv2 or later License URI: http://www.gnu.org/licenses/gpl-2.0.html Social Icon Widget is a very simple. Easily Manage This widget.
Customized Recent Comments
customized-recent-comments
Display recent comments on your blog with complete control over the layout and format of comments.
WordsTree Pocket Navigator Developer Profile
1 plugin · 0 total installs
How We Detect WordsTree Pocket Navigator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wtpn-pocket-nav/css/wtpn-pocket-nav-admin.css/wp-content/plugins/wtpn-pocket-nav/js/wtpn-pocket-nav-admin.jswtpn-pocket-nav/css/wtpn-pocket-nav-admin.css?ver=wtpn-pocket-nav/js/wtpn-pocket-nav-admin.js?ver=HTML / DOM Fingerprints
wtpn-pocket-nav-admin-csswtpn-pocket-nav-admin-jswtpn_pocket_nav_admin_object