ALL THE IPSUMS!!! Security & Risk Analysis

wordpress.org/plugins/all-the-ipsums

The ultimate lorem ipsum text generator for WordPress. No need for browsing dummy content, just use ALL THE ISPUMS!!!

70 active installs v1.0 PHP + WP 3.8+ Updated Jun 3, 2014
dummy-textgeneratoripsumloremlorem-ipsum
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ALL THE IPSUMS!!! Safe to Use in 2026?

Generally Safe

Score 85/100

ALL THE IPSUMS!!! has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "all-the-ipsums" v1.0 plugin presents a mixed security profile. On one hand, the absence of known CVEs and the complete reliance on prepared statements for SQL queries are strong positive indicators of good security practices. The static analysis also shows no dangerous functions, no external HTTP requests, and no taint analysis findings, which further contributes to a generally favorable outlook.

However, several significant concerns emerge from the code analysis. The most critical is the complete lack of output escaping across all identified output points. This represents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the absence of nonce checks and capability checks on the 7 shortcodes, which constitute the entire attack surface, means that any authenticated user could potentially trigger these shortcodes without proper authorization or validation, opening the door to unauthorized actions or information disclosure.

The plugin's vulnerability history being clean is a positive sign, but it does not negate the present risks identified in the static and taint analysis. The strength lies in its SQL handling and lack of external dependencies, but the weakness in output sanitization and authorization checks on its entry points requires immediate attention.

Key Concerns

  • 0% of output properly escaped
  • 0 nonce checks on entry points
  • 0 capability checks on entry points
Vulnerabilities
None known

ALL THE IPSUMS!!! Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ALL THE IPSUMS!!! Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

ALL THE IPSUMS!!! Attack Surface

Entry Points7
Unprotected0

Shortcodes 7

[zombie] index.php:34
[kitty] index.php:60
[bacon] index.php:85
[pommie] index.php:100
[skater] index.php:128
[metaphor] index.php:144
[batman] index.php:168
Maintenance & Trust

ALL THE IPSUMS!!! Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJun 3, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

ALL THE IPSUMS!!! Developer Profile

johnbhartley

1 plugin · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ALL THE IPSUMS!!!

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<p>bacon ipsum dolor amet turkey pastrami</p><p>bacon ipsum dolor amet shankle</p><p>bacon ipsum dolor amet tongue</p><p>bacon ipsum dolor amet drumstick</p>
FAQ

Frequently Asked Questions about ALL THE IPSUMS!!!