
Manage Calameo Publications by Athlon Security & Risk Analysis
wordpress.org/plugins/athlon-manage-calameo-publicationsThis plugin allows managing Calameo account(s) through WordPress.
Is Manage Calameo Publications by Athlon Safe to Use in 2026?
Generally Safe
Score 85/100Manage Calameo Publications by Athlon has a strong security track record. Known vulnerabilities have been patched promptly.
The 'athlon-manage-calameo-publications' plugin v1.1.1 exhibits significant security concerns, primarily stemming from its unprotected entry points and a lack of robust input validation and sanitization.
The static analysis reveals a considerable attack surface with 5 AJAX handlers, all of which lack authentication checks. This means any unauthenticated user can potentially trigger these functions, leading to an increased risk of exploitation. The presence of the 'unserialize' function is also a red flag, as it can be a vector for Remote Code Execution if not handled with extreme care and proper input validation. Furthermore, the taint analysis indicates that 3 out of 4 analyzed flows have unsanitized paths, with one identified as high severity, suggesting potential vulnerabilities like cross-site scripting or command injection.
The plugin's vulnerability history, though showing no currently unpatched CVEs, includes a medium severity Cross-site Scripting (XSS) vulnerability from 2014. While this specific vulnerability might be patched or less relevant now, the historical pattern, combined with the current findings of unsanitized taint flows and unprotected AJAX handlers, indicates a recurring weakness in how user-supplied data is handled. The low percentage of properly escaped outputs (4%) further exacerbates this risk, making it highly probable that stored or reflected XSS could be injected.
In conclusion, while the plugin uses prepared statements for its SQL queries, this single strength is overshadowed by critical weaknesses in its handling of AJAX requests, input sanitization, and output escaping. The large number of unprotected entry points presents a substantial risk that could be exploited by unauthenticated users, and the taint analysis strongly suggests the presence of exploitable vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flow
- Low output escaping percentage
- Dangerous function unserialize
- No nonce checks on AJAX handlers
- Limited capability checks
- Historical medium severity CVE (XSS)
Manage Calameo Publications by Athlon Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Manage Calameo Publications by Athlon < 1.1.1 - Reflected Cross-Site Scripting
Manage Calameo Publications by Athlon Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Manage Calameo Publications by Athlon Attack Surface
AJAX Handlers 5
WordPress Hooks 11
Maintenance & Trust
Manage Calameo Publications by Athlon Maintenance & Trust
Maintenance Signals
Community Trust
Manage Calameo Publications by Athlon Alternatives
WP Calameo
wp-calameo
This plugin allows to embed Calaméo publications in blog posts. Copy the WordPress embed code and paste it into your post.
Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files
embed-any-document
Embed PDF, DOC, PPT and XLS documents easily on your WordPress website with the help of Google Docs Viewer or Microsoft Office Online.
Simple File List
simple-file-list
Simple File List gives your WordPress website a list of your files which allows your users to open and download them.
Content Update Scheduler
content-update-scheduler
Schedule content updates for any WordPress page or post type.
Issues and Series for Newspapers, Magazines, Publishers, Writers
organize-series
PublishPress Series is the publishing plugin that allows you to organize posts into issues or series. This is ideal for magazines, newspapers, writers …
Manage Calameo Publications by Athlon Developer Profile
1 plugin · 10 total installs
How We Detect Manage Calameo Publications by Athlon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/athlon-manage-calameo-publications/css/styles.css/wp-content/plugins/athlon-manage-calameo-publications/js/scripts.js/wp-content/plugins/athlon-manage-calameo-publications/thickbox_content.php/wp-content/plugins/athlon-manage-calameo-publications/js/scripts.jsathlon-manage-calameo-publications/css/styles.css?ver=athlon-manage-calameo-publications/js/scripts.js?ver=HTML / DOM Fingerprints
ath_calameo_formdata-attachment-idath_delete_from_calameo_actionath_upload_to_calameo_actionathlon_calameo_admin_ajax_url