Charts And Graphs Manager Security & Risk Analysis

wordpress.org/plugins/charts-and-graphs-manager

Charts And Graphs Manager You can create different charts in this plugin.You can create a chart and use its shortcode on your custom page.

0 active installs v1.0 PHP + WP + Updated May 26, 2025
chartsmultiple-chart
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Charts And Graphs Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Charts And Graphs Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The "charts-and-graphs-manager" v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and SQL queries not using prepared statements are positive indicators. Notably, the plugin lacks any recorded CVEs, suggesting a history of responsible development or a lack of past discovered vulnerabilities, which is a strong positive signal. However, the lack of nonce checks and capability checks on its entry points, specifically the two shortcodes, presents a significant area of concern. While there are no explicit taint flows or unsanitized paths identified, the potential for privilege escalation or unauthorized actions through these unprotected shortcodes cannot be ruled out without further investigation of their internal logic. The output escaping is reasonably high, but the 17% that is not properly escaped could still lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in those outputs.

While the plugin's vulnerability history is clean, this does not automatically imply it is completely secure. The lack of critical or high severity issues in its history, coupled with the static analysis findings, suggests that the developers are likely following some security best practices. The primary weakness lies in the unprotected entry points, which is a common oversight that can be exploited. The partial output escaping also warrants attention. A balanced conclusion is that the plugin has a solid foundation but requires attention to its authorization and input sanitization mechanisms for its shortcodes to be considered robustly secure. The absence of critical static analysis findings is a strength, but the presence of potential weaknesses in unprotected entry points is a significant concern.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Output escaping not fully implemented
Vulnerabilities
None known

Charts And Graphs Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Charts And Graphs Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
44
218 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped262 total outputs
Attack Surface

Charts And Graphs Manager Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[CAGM-addallchart] includes\frontend\cagm_frontend.php:341
[CAGM-addchart] includes\frontend\cagm_frontend.php:713
WordPress Hooks 8
actioninitadmin\cagm_chart.php:35
actionadd_meta_boxesadmin\cagm_chart.php:47
actionsave_postadmin\cagm_chart.php:629
filtermanage_charts_posts_columnsadmin\cagm_chart.php:719
actionmanage_charts_posts_custom_columnadmin\cagm_chart.php:725
actionmanage_posts_extra_tablenavadmin\cagm_chart.php:732
actionadmin_enqueue_scriptscustom-chart-main.php:24
actionwp_enqueue_scriptscustom-chart-main.php:42
Maintenance & Trust

Charts And Graphs Manager Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 26, 2025
PHP min version
Downloads839

Community Trust

Rating60/100
Number of ratings1
Active installs0
Developer Profile

Charts And Graphs Manager Developer Profile

mgplugin

10 plugins · 850 total installs

97
trust score
Avg Security Score
95/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Charts And Graphs Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/charts-and-graphs-manager/admin/css/cagm_back.css/wp-content/plugins/charts-and-graphs-manager/admin/js/wp-color-picker-alpha.js/wp-content/plugins/charts-and-graphs-manager/admin/js/cagm_back_chart.js/wp-content/plugins/charts-and-graphs-manager/admin/js/chart.min.js
Script Paths
/wp-content/plugins/charts-and-graphs-manager/admin/js/wp-color-picker-alpha.js/wp-content/plugins/charts-and-graphs-manager/admin/js/cagm_back_chart.js/wp-content/plugins/charts-and-graphs-manager/admin/js/chart.min.js
Version Parameters
charts-and-graphs-manager/admin/css/cagm_back.css?ver=charts-and-graphs-manager/admin/js/cagm_back_chart.js?ver=charts-and-graphs-manager/admin/js/chart.min.js?ver=

HTML / DOM Fingerprints

Data Attributes
chart_typesline_chartscatter_chartchartchart_title_labelbubble_chart+25 more
JS Globals
jquerypostjs
Shortcode Output
<canvas id=new Chart(ctx,
FAQ

Frequently Asked Questions about Charts And Graphs Manager