Cinza Grid Security & Risk Analysis

wordpress.org/plugins/cinza-grid

A minimal grid plugin built with Isotope.

40 active installs v1.2.4 PHP 7.2+ WP 5.2+ Updated Dec 9, 2025
display-postgridisotopemetafizzypost-grid
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 21, 2025
Safety Verdict

Is Cinza Grid Safe to Use in 2026?

Generally Safe

Score 99/100

Cinza Grid has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 21, 2025Updated 3mo ago
Risk Assessment

The "cinza-grid" plugin version 1.2.4 exhibits a generally strong security posture based on the static analysis provided. The complete absence of dangerous functions, raw SQL queries, unescaped output, file operations, and external HTTP requests are all positive indicators. Furthermore, the presence of nonce and capability checks, alongside the use of prepared statements for SQL, suggests adherence to good security practices for the identified entry points. The taint analysis also shows no concerning flows, which further bolsters confidence in the code's sanitization efforts.

However, the plugin's vulnerability history presents a significant concern. The presence of one known CVE, even if currently unpatched by this version, indicates a past weakness that could potentially resurface or be exploited. The fact that the last vulnerability was recorded in late 2025, and is categorized as a medium severity Cross-site Scripting (XSS) vulnerability, points to a pattern of input validation issues in the past. While this version appears to have addressed it, the history warrants cautious monitoring and prompt updating should new vulnerabilities be discovered.

In conclusion, "cinza-grid" v1.2.4 demonstrates strengths in secure coding practices by effectively mitigating common web vulnerabilities like XSS, SQL injection, and insecure file operations. The lack of direct exposure through AJAX or REST API without checks is also commendable. The primary weakness lies in its historical vulnerability, specifically a past medium-severity XSS issue. While this version may have fixed it, the historical context necessitates vigilance and a commitment to keeping the plugin updated to the latest secure versions.

Key Concerns

  • Past medium severity CVE recorded
Vulnerabilities
1

Cinza Grid Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-11824medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cinza Grid <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Skin Content Field

Oct 21, 2025 Patched in 1.2.2 (2d)
Code Analysis
Analyzed Mar 16, 2026

Cinza Grid Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
241 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped241 total outputs
Attack Surface

Cinza Grid Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[cinzagrid] includes\backend-shortcodes.php:5
[cinza_grid] includes\backend-shortcodes.php:6
WordPress Hooks 13
actionwp_enqueue_scriptscinza-grid.php:23
actionadmin_enqueue_scriptscinza-grid.php:42
actioninitincludes\backend-cpts.php:7
filterset_custom_edit_cinza_grid_columnsincludes\backend-cpts.php:72
actionmanage_cinza_grid_posts_custom_columnincludes\backend-cpts.php:78
filtermanage_cinza_grid_posts_columnsincludes\backend-cpts.php:87
filterthe_contentincludes\backend-cpts.php:103
actionadmin_headincludes\backend-cpts.php:112
filterrank_math/sitemap/exclude_post_typeincludes\backend-cpts.php:130
filterrank_math/frontend/robotsincludes\backend-cpts.php:143
actionadd_meta_boxesincludes\backend-cpts.php:164
actionsave_postincludes\backend-cpts.php:666
actioninitincludes\backend-shortcodes.php:3
Maintenance & Trust

Cinza Grid Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version7.2
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Cinza Grid Developer Profile

Cinza Web Design

2 plugins · 140 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
2 days
View full developer profile
Detection Fingerprints

How We Detect Cinza Grid

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cinza-grid/assets/css/animate.min.css/wp-content/plugins/cinza-grid/assets/css/frontend-style.css/wp-content/plugins/cinza-grid/assets/js/isotope.pkgd.min.js/wp-content/plugins/cinza-grid/assets/js/frontend-script.js/wp-content/plugins/cinza-grid/assets/css/backend-admin.css/wp-content/plugins/cinza-grid/assets/css/backend-style.css/wp-content/plugins/cinza-grid/assets/js/backend-script.js
Script Paths
/wp-content/plugins/cinza-grid/assets/js/frontend-script.js/wp-content/plugins/cinza-grid/assets/js/backend-script.js
Version Parameters
cinza-grid/assets/css/animate.min.css?ver=cinza-grid/assets/css/frontend-style.css?ver=cinza-grid/assets/js/isotope.pkgd.min.js?ver=cinza-grid/assets/js/frontend-script.js?ver=cinza-grid/assets/css/backend-admin.css?ver=cinza-grid/assets/css/backend-style.css?ver=cinza-grid/assets/js/backend-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
cgrid-error
Shortcode Output
<p class='cgrid-error'>ERROR: Please enter a valid Cinza Grid ID.</p><p class='cgrid-error'>ERROR: This Cinza Grid is not published yet.</p><p class='cgrid-error'>ERROR: The Cinza Grid does not exist or has been deleted.</p>
FAQ

Frequently Asked Questions about Cinza Grid