
ArtPlacer Widget Security & Risk Analysis
wordpress.org/plugins/artplacer-widgetAllow your visitors visualize how artworks look on walls as soon as they land on your website!
Is ArtPlacer Widget Safe to Use in 2026?
Use With Caution
Score 67/100ArtPlacer Widget has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'artplacer-widget' v2.23.2 plugin exhibits a mixed security posture. While the static analysis reveals a relatively small attack surface with no directly unprotected AJAX handlers or REST API routes, and no file operations or external HTTP requests, significant concerns arise from the code signals and vulnerability history. The low percentage of SQL queries using prepared statements (18%) and the similarly low percentage of properly escaped output (5%) are major red flags. These indicate a high likelihood of vulnerabilities like SQL Injection and Cross-Site Scripting, which are corroborated by the plugin's past vulnerability history. The plugin has a concerning history of 5 known CVEs, with one still unpatched, and a majority of these being medium or high severity. Common vulnerability types include XSS, SQL Injection, CSRF, and Missing Authorization, all of which point to fundamental weaknesses in input validation and authorization. The presence of an unpatched high-severity vulnerability, coupled with the code's apparent lack of robust sanitization and escaping, suggests a substantial ongoing risk to WordPress sites using this plugin.
Key Concerns
- Unpatched High Severity CVE
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- No capability checks found
- 5 known CVEs in history
ArtPlacer Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
ArtPlacer Widget <= 2.23.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
ArtPlacer Widget <= 2.22.9.2 - Authenticated (Contributor+) SQL Injection
ArtPlacer Widget <= 2.21.1 - Cross-Site Request Forgery
ArtPlacer Widget <= 2.21.1 - Missing Authorization to Widget Deletion
ArtPlacer Widget <= 2.20.6 - Authenticated (Editor+) SQL Injection
ArtPlacer Widget Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ArtPlacer Widget Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 16
Maintenance & Trust
ArtPlacer Widget Maintenance & Trust
Maintenance Signals
Community Trust
ArtPlacer Widget Alternatives
Wizart Visualizer — AI-Powered Room Visualization
wizart-home-interior-design-solutions
We help thousands of home improvement retailers and manufacturers all over the globe to lower returns and sell more with Wizart visualizer.
Redirect 404 to Homepage
404-to-homepage
Redirect 404 missing pages to the homepage using SEO 301 redirection. Super lightweight!
Super Progressive Web Apps
super-progressive-web-apps
SuperPWA helps you convert your WordPress website into a Progressive Web App instantly.
Clever Fox
clever-fox
Clever Fox plugin to enhance the functionality of free themes made by Nayra Themes.
Desert Companion
desert-companion
Desert Companion Enhances Desert Themes with additional functionality.
ArtPlacer Widget Developer Profile
1 plugin · 200 total installs
How We Detect ArtPlacer Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/artplacer-widget/assets/css/style.css/wp-content/plugins/artplacer-widget/assets/js/custom.js/wp-content/plugins/artplacer-widget/assets/css/front.css/wp-content/plugins/artplacer-widget/assets/js/artplacer-widget-front.jshttps://widget.artplacer.com/js/script.js/wp-content/plugins/artplacer-widget/assets/js/artplacer-widget.jsartplacer-widget/assets/css/style.css?ver=artplacer-widget/assets/js/custom.js?ver=artplacer-widget/assets/css/front.css?ver=artplacer-widget/assets/js/artplacer-widget-front.js?ver=HTML / DOM Fingerprints
data-artplacer-widgetartplacer-widgetartplacerWidgetartplacerWidgetConfig/wp-json/artplacer-widget/v1<artplacer>