Cite Security & Risk Analysis

wordpress.org/plugins/cite

Help readers know how to cite your article correctly

100 active installs v1.2.2 PHP + WP 3.1+ Updated Jul 29, 2015
citationcitereferencereferencing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cite Safe to Use in 2026?

Generally Safe

Score 85/100

Cite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'cite' plugin v1.2.2 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are positive indicators. The limited attack surface, consisting of only one shortcode and no AJAX handlers or REST API routes, further contributes to a reduced threat landscape. The plugin also lacks any recorded vulnerability history, suggesting a stable and secure past.

However, a significant concern arises from the output escaping. With 2 total outputs and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered by the plugin that is not explicitly escaped could be exploited by an attacker to inject malicious scripts, leading to session hijacking, credential theft, or defacement. While the plugin has no known vulnerabilities and a small attack surface, this unescaped output presents a clear and present danger that requires immediate attention.

In conclusion, while the 'cite' plugin shows strengths in its limited attack surface and lack of recorded vulnerabilities, the critical deficiency in output escaping presents a major security weakness. This flaw significantly outweighs the positive aspects and should be the primary focus for remediation to ensure the plugin's security.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

Cite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Cite Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cite] cite.php:91
WordPress Hooks 4
actionadmin_initcite.php:27
actionadmin_menucite.php:34
actionwp_headcite.php:110
actionadmin_headcite.php:120
Maintenance & Trust

Cite Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedJul 29, 2015
PHP min version
Downloads5K

Community Trust

Rating90/100
Number of ratings15
Active installs100
Developer Profile

Cite Developer Profile

Maeve Lander

6 plugins · 11K total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
29 days
View full developer profile
Detection Fingerprints

How We Detect Cite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wpcpwpcp-adminwpcp-textareawpcp-templates-info
Shortcode Output
<div class="wpcp">{author}, "{title}," in <em>{sitename}</em>, {publication_date}, {permalink}.{author}, "{title}," {sitename}, {publication_date}, {permalink}.{author}, "{title}," in {sitename}, ed. Jack Dougherty (Ann Arbor: Michigan Publishing, 2014), {permalink}.
FAQ

Frequently Asked Questions about Cite