About Me Image Widget by Angie Makes Security & Risk Analysis

wordpress.org/plugins/about-me-image-widget

Add "About Me" image widget, with caption and link, to any widget area.

200 active installs v1.4.3 PHP + WP 4.2.4+ Updated May 10, 2017
about-meabout-me-imageabout-me-image-widgetimage-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is About Me Image Widget by Angie Makes Safe to Use in 2026?

Generally Safe

Score 85/100

About Me Image Widget by Angie Makes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'about-me-image-widget' plugin v1.4.3 demonstrates a generally good security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, cron events, and file operations significantly limits the potential attack surface. Furthermore, the plugin utilizes prepared statements for all its SQL queries and avoids external HTTP requests, which are crucial security practices. The lack of any identified dangerous functions or taint flows further strengthens this positive assessment. However, a significant concern arises from the low percentage of properly escaped output (39%). This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data, if not properly sanitized and escaped before being displayed, could be injected and executed by a visitor's browser. The plugin's vulnerability history is notably clean, with no recorded CVEs, which is a strong positive indicator. In conclusion, while the plugin excels in limiting its attack surface and handling database interactions securely, the prevalence of unescaped output represents a critical weakness that requires immediate attention to mitigate XSS risks.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

About Me Image Widget by Angie Makes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

About Me Image Widget by Angie Makes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

39% escaped56 total outputs
Attack Surface

About Me Image Widget by Angie Makes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_enqueue_scriptsabout-me-image-widget.php:32
actionwidgets_initabout-me-image-widget.php:37
Maintenance & Trust

About Me Image Widget by Angie Makes Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMay 10, 2017
PHP min version
Downloads11K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

About Me Image Widget by Angie Makes Developer Profile

Chris Baldelomar

5 plugins · 3K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect About Me Image Widget by Angie Makes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/about-me-image-widget/css/admin.css/wp-content/plugins/about-me-image-widget/js/admin.js
Script Paths
/wp-content/plugins/about-me-image-widget/js/admin.js
Version Parameters
about-me-image-widget/css/admin.css?ver=about-me-image-widget/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpc-image-wrapperwpc-widgets-image-fieldwpc-widgets-preview-imagewpc-widget-img-containersidebar-caption
Data Attributes
data-targetdata-previewdata-framedata-statedata-fetchdata-title+2 more
FAQ

Frequently Asked Questions about About Me Image Widget by Angie Makes