
YD WPMU Bloglist Widget Security & Risk Analysis
wordpress.org/plugins/yd-wpmu-bloglist-widgetSidebar widget and template function to display an ordered blog list of subsites (with post count) on a page of the WordPress MU main site.
Is YD WPMU Bloglist Widget Safe to Use in 2026?
Generally Safe
Score 85/100YD WPMU Bloglist Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The yd-wpmu-bloglist-widget plugin v2.1.1 exhibits a mixed security posture. While the absence of known CVEs and a seemingly small attack surface are positive indicators, the static analysis reveals significant areas of concern. Notably, a very low percentage of outputs are properly escaped (4%), which is a critical weakness. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be directly injected into the output without sanitization. Furthermore, the taint analysis shows two flows with unsanitized paths, though no critical or high severity vulnerabilities were flagged, the presence of these flows without proper sanitization warrants attention. The lack of nonce checks and capability checks across all entry points, combined with the low output escaping rate, suggests a lack of robust input validation and authorization mechanisms. The SQL query usage is somewhat concerning as well, with 33% of queries potentially not using prepared statements, posing a risk of SQL injection if user input is involved in constructing these queries. The vulnerability history is clean, which is a strong positive, suggesting good past development practices or a lack of past targeted attacks. However, the current code analysis findings present a considerable risk that must be addressed.
Key Concerns
- Low output escaping rate (4%)
- Two unsanitized path flows in taint analysis
- No nonce checks
- No capability checks
- Significant percentage of SQL queries not prepared
YD WPMU Bloglist Widget Security Vulnerabilities
YD WPMU Bloglist Widget Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
YD WPMU Bloglist Widget Attack Surface
WordPress Hooks 6
Maintenance & Trust
YD WPMU Bloglist Widget Maintenance & Trust
Maintenance Signals
Community Trust
YD WPMU Bloglist Widget Alternatives
Advanced Posts Listing – Show Post List Easily
advanced-posts-listing
Display posts list from posts, pages or custom post types. Use Multiple designs and filters.
Disable User Gravatar
disable-user-gravatar
Stops WordPress from grabbing a user avatar using their registrated email from gravatar.com.
YD Network-wide Options
yd-wpmu-sitewide-options
This plugin has been thoroughly tested and is fully compatible with WordPress 3.0x multisite or with WPMU 2.9.
Add Link
add-link
Add Link enables your users to add links to your blog.
bbRedirector
bbredirector
bbRedirector makes it easy to redirect a page to another location using absolute urls.
YD WPMU Bloglist Widget Developer Profile
14 plugins · 180 total installs
How We Detect YD WPMU Bloglist Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yd-wpmu-bloglist-widget/css/style.css/wp-content/plugins/yd-wpmu-bloglist-widget/js/yd-wpmubl-admin.js/wp-content/plugins/yd-wpmu-bloglist-widget/js/yd-wpmubl-admin.js/wp-content/plugins/yd-wpmu-bloglist-widget/css/style.css?ver=/wp-content/plugins/yd-wpmu-bloglist-widget/js/yd-wpmubl-admin.js?ver=HTML / DOM Fingerprints
blog_blockblog_listpost_count<!-- Original development of this plugin was kindly funded by http://www.pressonline.com --><!-- Spanish and Galician translation kindly provided by: Arume @ http://www.arumeinformatica.es/ --><!-- Dutch translation kindly provided by: Rene @ http://www.fethiyehotels.com --><!-- German translation by Rian Kramer @ Pangaea http://www.pangaea.nl -->+50 moreyd-wpmubl_versionhome_bottomlinkhome_bottomtextcolumn_countbefore_blockafter_block+25 moreyd_wpmubl_version