Apalpador Security & Risk Analysis

wordpress.org/plugins/apalpador

Adds the traditional Galician Christmas character "Apalpador" to your WordPress site with festive visual effects.

10 active installs v2.0.0 PHP 7.4+ WP 5.0+ Updated Dec 26, 2025
apalpadorchristmasdecorationgaliciasnow
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Apalpador Safe to Use in 2026?

Generally Safe

Score 100/100

Apalpador has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin 'apalpador' v2.0.0 presents a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code shows excellent practices regarding SQL queries, with 100% using prepared statements, and a very high percentage of output properly escaped. The lack of file operations and external HTTP requests further reduces potential vulnerabilities. The presence of capability checks, even with a low count, indicates some consideration for access control.

However, the complete absence of taint analysis results (0 flows analyzed) is a significant concern. While this might imply no taint flows were found, it could also indicate that the analysis was incomplete or not performed. The lack of nonce checks, while not directly tied to an attack surface in this specific analysis, is a fundamental security practice for many WordPress interactions and its absence warrants attention. The vulnerability history is clean, showing no known CVEs, which is a positive indicator. Overall, the plugin appears to follow good security practices in its current form, with its strengths lying in its minimal attack surface and secure handling of SQL and output. The primary area for improvement and potential concern is the lack of comprehensive taint analysis and the absence of nonce checks.

Key Concerns

  • Missing nonce checks
  • Incomplete taint analysis results
Vulnerabilities
None known

Apalpador Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Apalpador Release Timeline

v2.0.0Current
Code Analysis
Analyzed Mar 17, 2026

Apalpador Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
121 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped125 total outputs
Attack Surface

Apalpador Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedapalpador.php:72
actionadmin_menuincludes\class-apalpador-admin.php:33
actionadmin_initincludes\class-apalpador-admin.php:34
actionadmin_enqueue_scriptsincludes\class-apalpador-admin.php:35
actionwpincludes\class-apalpador-frontend.php:26
actionwp_enqueue_scriptsincludes\class-apalpador-frontend.php:39
actionwp_footerincludes\class-apalpador-frontend.php:44
Maintenance & Trust

Apalpador Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 26, 2025
PHP min version7.4
Downloads182

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Apalpador Developer Profile

Anxo Sánchez

3 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Apalpador

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apalpador/assets/css/admin.css/wp-content/plugins/apalpador/assets/js/admin.js/wp-content/plugins/apalpador/assets/css/frontend.css/wp-content/plugins/apalpador/assets/js/frontend.js/wp-content/plugins/apalpador/assets/js/vendor/lottie.min.js
Script Paths
/wp-content/plugins/apalpador/assets/js/admin.js/wp-content/plugins/apalpador/assets/js/frontend.js/wp-content/plugins/apalpador/assets/js/vendor/lottie.min.js
Version Parameters
apalpador/assets/css/admin.css?ver=apalpador/assets/js/admin.js?ver=apalpador/assets/css/frontend.css?ver=apalpador/assets/js/frontend.js?ver=apalpador/assets/js/vendor/lottie.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
apalpador-containerapalpador-bubble
Data Attributes
data-apalpador-lottie-animdata-apalpador-lottie-loopdata-apalpador-lottie-autoplaydata-apalpador-lottie-directiondata-apalpador-lottie-rendererdata-apalpador-animation-speed
JS Globals
apalpadorAdmin
FAQ

Frequently Asked Questions about Apalpador