
Glossary Security & Risk Analysis
wordpress.org/plugins/automatic-glossaryGiven a collection of glossary definition pages, automatically creates links in your page and post content for the words in your glossary.
Is Glossary Safe to Use in 2026?
Generally Safe
Score 85/100Glossary has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "automatic-glossary" plugin v0.9 reveals a generally clean codebase with no identified dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, or external HTTP requests. The plugin also has a complete absence of known CVEs, indicating a strong track record of security maintenance. However, a significant concern arises from the complete lack of output escaping. This means that any dynamic content rendered by the plugin could potentially be vulnerable to Cross-Site Scripting (XSS) attacks if the input isn't meticulously sanitized elsewhere. Furthermore, the absence of any identified capability checks or nonce checks, despite having potential entry points (though none are listed as unprotected in the static analysis), suggests a reliance on the underlying WordPress environment for authorization, which might not be sufficient in all scenarios. The lack of any identified taint flows is positive, but the unescaped output remains a critical gap.
Key Concerns
- All outputs are unescaped
- No capability checks found
- No nonce checks found
Glossary Security Vulnerabilities
Glossary Code Analysis
Output Escaping
Glossary Attack Surface
WordPress Hooks 3
Maintenance & Trust
Glossary Maintenance & Trust
Maintenance Signals
Community Trust
Glossary Alternatives
mowsterGlossary
mowster-glossary
Allows to manage and display a glossary in WordPress.
Duplicate Post
copy-delete-posts
Duplicate post
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
CMS Tree Page View
cms-tree-page-view
Adds a tree view of all pages & custom posts. Get a great overview + options to drag & drop to reorder & option to add multiple pages.
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
Glossary Developer Profile
1 plugin · 10 total installs
How We Detect Glossary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
glossaryLinkdelete<div id="glossaryList"></div>