
AS Project Portfolio Security & Risk Analysis
wordpress.org/plugins/as-project-portfolioA simple plugin to add a custom post type for managing and displaying project portfolios with a shortcode and admin dashboard.
Is AS Project Portfolio Safe to Use in 2026?
Generally Safe
Score 100/100AS Project Portfolio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'as-project-portfolio' plugin version 1.0.0 demonstrates a strong security posture based on the provided static analysis. The code adheres to several critical security best practices, including the exclusive use of prepared statements for all SQL queries, 100% proper output escaping, and the presence of nonce and capability checks for its entry points. The absence of dangerous functions, file operations, and external HTTP requests further minimizes potential attack vectors. The plugin also boasts a clean vulnerability history, with no recorded CVEs, which suggests a history of secure development or proactive security patching.
Despite the positive findings, the analysis indicates a potential area for scrutiny: the plugin has only one identified entry point (a shortcode) and no AJAX handlers or REST API routes. While this limits the attack surface significantly, it's crucial to ensure that this single shortcode is robustly implemented and doesn't inadvertently introduce vulnerabilities, especially if it handles user-supplied data indirectly. The lack of any taint flows or critical/high severity issues in the taint analysis is a significant strength. The current version appears to be secure based on the data, but ongoing vigilance and testing remain important.
In conclusion, 'as-project-portfolio' v1.0.0 exhibits excellent security fundamentals. Its adherence to secure coding practices and lack of vulnerability history are commendable. The limited attack surface, while a benefit, should be continuously monitored to ensure no new vulnerabilities are introduced in future updates. Overall, the plugin presents a low risk to WordPress installations.
AS Project Portfolio Security Vulnerabilities
AS Project Portfolio Code Analysis
Output Escaping
AS Project Portfolio Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
AS Project Portfolio Maintenance & Trust
Maintenance Signals
Community Trust
AS Project Portfolio Alternatives
Portfolio CPT
portfolio-cpt
Enables a 'Portfolio' type and 'Portfolio Tags' taxonomy.
Prjcts
prjcts
Effortlessly create a custom post type to organize projects with custom categories and flexible URL settings, perfect for WordPress theme developers.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
WPZOOM Portfolio Lite – Filterable Portfolio Plugin
wpzoom-portfolio
Portfolio plugin for WordPress. Create filterable portfolio grids with masonry layouts and lightbox. Ideal for photographers, designers, agencies.
AS Project Portfolio Developer Profile
2 plugins · 0 total installs
How We Detect AS Project Portfolio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/as-project-portfolio/assets/css/style.css/wp-content/plugins/as-project-portfolio/assets/js/script.js/wp-content/plugins/as-project-portfolio/assets/js/script.jsas-project-portfolio/assets/css/style.css?ver=as-project-portfolio/assets/js/script.js?ver=HTML / DOM Fingerprints
project-itemname="project_description"name="project_client"name="project_date"name="project_url"name="as_pp_save_project_meta_nonce_field"<div class='project-item'><h2><a href='' target='_blank'></a></h2>