BibleScriptureTagger Security & Risk Analysis

wordpress.org/plugins/biblescripturetagger

BibleScriptureTagger Creates a hover for Bible references and reveals the verse text and provides a link for further study at the Bible Portal.

10 active installs v1.0.1 PHP 7.0+ WP 2.3+ Updated Jul 4, 2023
biblescripturescripturesscripturetaggerverse
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is BibleScriptureTagger Safe to Use in 2026?

Generally Safe

Score 85/100

BibleScriptureTagger has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "biblescripturetagger" v1.0.1 plugin exhibits an excellent security posture based on the provided static analysis. Its attack surface is zero, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed, indicating a very limited entry point for potential attackers. Crucially, all detected SQL queries are properly prepared, and all output is correctly escaped, significantly mitigating common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The presence of nonce and capability checks further reinforces its secure design. The plugin's vulnerability history is also clean, with no recorded CVEs, which suggests a history of secure development or a lack of past exploitation.

While the static analysis reveals no immediate code-level vulnerabilities, the lack of any entry points is unusual for a plugin that likely needs to interact with WordPress in some way. This could mean its functionality is entirely client-side or relies on hooks that are not directly exposed as entry points in this analysis. However, based solely on the provided data, the plugin demonstrates strong adherence to secure coding practices. The absence of any identified taint flows with unsanitized paths or dangerous functions is a significant strength. The plugin's track record of zero known vulnerabilities further bolsters confidence in its security. Overall, this plugin appears to be very securely coded, with no apparent weaknesses identified in the static analysis or historical vulnerability data.

Vulnerabilities
None known

BibleScriptureTagger Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BibleScriptureTagger Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
bible_scripture_tagger_options_update (bible-scripture-tagger.php:141)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

BibleScriptureTagger Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menubible-scripture-tagger.php:168
actionwp_footerbible-scripture-tagger.php:196
Maintenance & Trust

BibleScriptureTagger Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 4, 2023
PHP min version7.0
Downloads991

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

BibleScriptureTagger Developer Profile

kevinarise

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BibleScriptureTagger

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://bibleportal.com/assets/scripts/bp-scripture-tagger-min.js

HTML / DOM Fingerprints

JS Globals
BP.ScriptureTagger.Config.Translation
FAQ

Frequently Asked Questions about BibleScriptureTagger