Atr Portfolio Security & Risk Analysis

wordpress.org/plugins/atr-portfolio

Portfolio block. Showcase your projects and portfolio work.

100 active installs v1.0.0 PHP 7.0+ WP 5.8+ Updated Jan 12, 2025
blockgutenbergportfolio
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Atr Portfolio Safe to Use in 2026?

Generally Safe

Score 92/100

Atr Portfolio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "atr-portfolio" v1.0.0 plugin exhibits a seemingly strong security posture based on the provided static analysis. There are no identified entry points such as AJAX handlers, REST API routes, or shortcodes, which significantly limits the plugin's attack surface. Furthermore, the absence of dangerous functions, SQL queries without prepared statements, and unescaped output are all positive indicators of good coding practices. The plugin also has no recorded vulnerability history, which is a very positive sign.

However, the complete lack of nonces and capability checks across all potential entry points (even though there are zero identified) is a notable concern. While the current attack surface is zero, if any functionality were to be added in the future without these security measures, it would immediately become vulnerable. The zero taint flows analyzed are also neutral; it suggests no issues were found, but it could also indicate limited analysis depth. The absence of any reported CVEs is excellent, but a lack of history doesn't guarantee future immunity.

In conclusion, the plugin appears secure in its current state due to a minimal attack surface and good coding hygiene. The primary weakness lies in the potential for future vulnerabilities if new features are added without implementing essential security checks like nonces and capability checks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Atr Portfolio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Atr Portfolio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Atr Portfolio Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitatr-portfolio.php:27
actioninitatr-portfolio.php:38
Maintenance & Trust

Atr Portfolio Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 12, 2025
PHP min version7.0
Downloads14K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Atr Portfolio Developer Profile

yehudaT

7 plugins · 940 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Atr Portfolio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/atr-portfolio/build/index.js/wp-content/plugins/atr-portfolio/build/style-index.css/wp-content/plugins/atr-portfolio/blocks/portfolio-item/build/index.js/wp-content/plugins/atr-portfolio/blocks/portfolio-item/build/style-index.css
Script Paths
/wp-content/plugins/atr-portfolio/build/index.js/wp-content/plugins/atr-portfolio/blocks/portfolio-item/build/index.js

HTML / DOM Fingerprints

JS Globals
atr_portfolio_OBJ
FAQ

Frequently Asked Questions about Atr Portfolio