
Tarot Card Oracle Security & Risk Analysis
wordpress.org/plugins/card-oracleCreate tarot, oracle, cartouche, and rune readings on your WordPress site using your own decks, spreads, and meanings.
Is Tarot Card Oracle Safe to Use in 2026?
Generally Safe
Score 100/100Tarot Card Oracle has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "card-oracle" plugin version 1.2.1 presents a mixed security posture. On the positive side, the plugin exhibits a strong commitment to secure coding practices with a high percentage of SQL queries using prepared statements and a significant majority of output being properly escaped. The absence of any known CVEs or recorded vulnerability history suggests a stable and likely well-maintained codebase. Furthermore, the presence of a substantial number of nonce and capability checks indicates an awareness of common WordPress security vulnerabilities.
However, there are notable areas of concern that impact its overall security. The plugin exposes three AJAX handlers without authentication checks, creating a potential attack surface for unauthorized actions. While no critical or high severity taint flows were identified, the presence of three flows with unsanitized paths, even if not deemed critical, warrants careful review. The plugin also bundles Freemius v1.0, which could potentially be an outdated library depending on its release date and known vulnerabilities.
In conclusion, "card-oracle" v1.2.1 benefits from good internal coding hygiene regarding SQL and output escaping, and its clean vulnerability history is a strong indicator of security. The primary weaknesses lie in the unprotected AJAX endpoints and the potential risk associated with unsanitized path flows. Addressing these specific areas would significantly strengthen the plugin's security posture.
Key Concerns
- AJAX handlers without authentication
- Flows with unsanitized paths (3 total)
- Bundled outdated library (Freemius v1.0)
Tarot Card Oracle Security Vulnerabilities
Tarot Card Oracle Release Timeline
Tarot Card Oracle Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Tarot Card Oracle Attack Surface
AJAX Handlers 3
REST API Routes 1
Shortcodes 6
WordPress Hooks 59
Scheduled Events 1
Maintenance & Trust
Tarot Card Oracle Maintenance & Trust
Maintenance Signals
Community Trust
Tarot Card Oracle Alternatives
Tarot, Oracle cards, Tarot readings, Tarokina
tarokina-free
The best tarot plugin for wordpress. Intuitive and easy to use. Provides accurate tarot readings.
Norse Rune Oracle Plugin
norse-runes-oracle
The Norse Runes Oracle Plugin allows you to interpret single runes or do rune castings.
Daily Tarot
daily-tarot
Daily Tarot helps you publish, schedule, and share tarot readings on WordPress - perfect for creating a consistent Card of the Day experience.
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress
oracle-cards
Interactive Card Deck Plugin for WordPress
EZ Horoscope Professional
ez-horoscope
Astrologically accurate horoscopes with cosmic insights, advice, birth charts, and AI voice agents for chatting about readings.
Tarot Card Oracle Developer Profile
1 plugin · 100 total installs
How We Detect Tarot Card Oracle
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/card-oracle/admin/css/card-oracle-admin.css/wp-content/plugins/card-oracle/admin/js/card-oracle-admin.js/wp-content/plugins/card-oracle/public/css/card-oracle-public.css/wp-content/plugins/card-oracle/public/js/card-oracle-public.js/wp-content/plugins/card-oracle/admin/js/card-oracle-admin.js/wp-content/plugins/card-oracle/public/js/card-oracle-public.jscard-oracle/admin/css/card-oracle-admin.css?ver=card-oracle/admin/js/card-oracle-admin.js?ver=card-oracle/public/css/card-oracle-public.css?ver=card-oracle/public/js/card-oracle-public.js?ver=HTML / DOM Fingerprints
card-oracle-admin-section-wrappercard-oracle-settings-tab-navcard-oracle-settings-tab-content<!-- Card Oracle Settings --><!-- BEGIN Card Oracle General Settings --><!-- END Card Oracle General Settings -->data-tabdata-tab-contentcardOracleAdmin/wp-json/card-oracle/v1/settings/wp-json/card-oracle/v1/cards/wp-json/card-oracle/v1/spreads/wp-json/card-oracle/v1/readings[card_oracle_reading][card_oracle_deck]