Academic Publications Showcase Security & Risk Analysis

wordpress.org/plugins/academic-publications-showcase

Display publications from Zenodo communities or ORCID author profiles with modern card layouts and customizable designs.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Mar 8, 2026
academicorcidpublicationsresearchzenodo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Academic Publications Showcase Safe to Use in 2026?

Generally Safe

Score 100/100

Academic Publications Showcase has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 26d ago
Risk Assessment

The academic-publications-showcase v1.0.0 plugin demonstrates a generally good security posture, with all identified entry points having 100% output escaping and no critical or high severity taint flows. The absence of dangerous functions and file operations further contributes to its positive security profile. The plugin also has no recorded vulnerability history, suggesting a stable and likely secure codebase. However, there are a few areas that warrant attention. The plugin lacks any nonce checks, which is a significant oversight for potential cross-site request forgery (CSRF) vulnerabilities, especially if any of the entry points are leveraged in a way that modifies data or performs sensitive actions. Furthermore, the presence of raw SQL queries, even if a majority use prepared statements, introduces a potential for SQL injection if not handled meticulously. The single external HTTP request should also be monitored for potential vulnerabilities in the external service.

While the plugin's strengths lie in its robust output escaping and lack of critical code signals, the absence of nonce checks and the existence of non-prepared SQL queries are notable weaknesses. The vulnerability history being clean is a positive indicator but does not guarantee future security. The plugin's low attack surface is a mitigating factor, but the identified vulnerabilities, however minor they may appear in isolation, could be exploited in combination or if the plugin's functionality expands. A cautious approach is recommended, prioritizing the implementation of nonce checks and auditing the SQL queries.

Key Concerns

  • Missing nonce checks on entry points
  • Raw SQL queries present
Vulnerabilities
None known

Academic Publications Showcase Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Academic Publications Showcase Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
0
188 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

67% prepared3 total queries

Output Escaping

100% escaped188 total outputs
Attack Surface

Academic Publications Showcase Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[showcase-publications] includes\class-aps.php:126
WordPress Hooks 7
actionadmin_enqueue_scriptsincludes\class-aps.php:100
actionadmin_enqueue_scriptsincludes\class-aps.php:101
actionadmin_initincludes\class-aps.php:104
actionadmin_menuincludes\class-aps.php:106
actionwp_enqueue_scriptsincludes\class-aps.php:120
actionwp_enqueue_scriptsincludes\class-aps.php:121
filterquery_varsincludes\class-aps.php:123
Maintenance & Trust

Academic Publications Showcase Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 8, 2026
PHP min version7.4
Downloads134

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Academic Publications Showcase Developer Profile

havacekm

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Academic Publications Showcase

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/academic-publications-showcase/admin/css/aps-admin.css/wp-content/plugins/academic-publications-showcase/admin/js/aps-admin.js
Script Paths
/wp-content/plugins/academic-publications-showcase/admin/js/aps-admin.js
Version Parameters
academic-publications-showcase/admin/css/aps-admin.css?ver=academic-publications-showcase/admin/js/aps-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
dyzc-admin-wrapdyzc-tab-contentdyzc-sectiondyzc-help-textdyzc-recommendeddyzc-usage-carddyzc-code-blockdyzc-example
JS Globals
window.jQuery
FAQ

Frequently Asked Questions about Academic Publications Showcase