
Citation Manager Security & Risk Analysis
wordpress.org/plugins/citation-managerCitation Manager - Management and display of external, manual citations to WordPress content
Is Citation Manager Safe to Use in 2026?
Generally Safe
Score 85/100Citation Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "citation-manager" plugin v0.9.6 exhibits a mixed security posture. On the positive side, it has a relatively small attack surface with all identified entry points (AJAX, shortcodes) appearing to have authentication and capability checks. The absence of file operations, external HTTP requests, and known historical vulnerabilities are also encouraging signs. However, several significant concerns are raised by the static analysis. The presence of the `unserialize` function is a critical danger signal, especially when combined with insufficient output escaping. While no critical or high severity taint flows were identified in this specific analysis, the combination of unsanitized paths in taint flows and the potential for unserialization vulnerabilities creates a substantial risk. The plugin also shows a worrying lack of proper output escaping, with 0% of outputs being correctly handled, leaving it open to Cross-Site Scripting (XSS) attacks. The low percentage of SQL queries using prepared statements also indicates a potential for SQL injection vulnerabilities, though this is somewhat mitigated by the small number of queries. Overall, while the plugin has a clean vulnerability history and a somewhat protected attack surface, the dangerous functions, lack of output escaping, and potential for SQL injection create a considerable risk that needs urgent attention.
Key Concerns
- Dangerous function unserialize found
- No properly escaped output found
- Low percentage of prepared SQL statements
- Taint flows with unsanitized paths
Citation Manager Security Vulnerabilities
Citation Manager Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Citation Manager Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 11
Maintenance & Trust
Citation Manager Maintenance & Trust
Maintenance Signals
Community Trust
Citation Manager Alternatives
WebMan Amplifier
webman-amplifier
Amplifies functionality of WP themes. Provides custom post types, shortcodes, metaboxes, icons. Theme developer's best friend!
Get Custom Field Values
get-custom-field-values
Use widgets, shortcodes, and/or template tags to easily retrieve and display custom field values for posts or pages.
Flexia Core
flexia-core
Core plugin for Flexia theme. Controls all the plugin territory functionality for Flexia.
Meta Content
meta
A meta box which helps us to add content or scripts to any part of the website, on each individual post/page. Easy to Implement with Shortcode.
Bildquellenangaben
bildquellen-copyright-statement
Bildquellen für jedes Bild ganz einfach vergeben.
Citation Manager Developer Profile
3 plugins · 90 total installs
How We Detect Citation Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/citation-manager/citations-admin.css/wp-content/plugins/citation-manager/citations.cssHTML / DOM Fingerprints
citationcitationscitation-dumpcitation-post-titlecitation-list[citation-count-total][citation-count][citation-dump]