Cite references Security & Risk Analysis

wordpress.org/plugins/cite-references

A plugin that will include cite referencing on your site.

10 active installs v1.0 PHP + WP 3.0.1+ Updated May 14, 2015
cite-referencingciting-referenceonline-quotations
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cite references Safe to Use in 2026?

Generally Safe

Score 85/100

Cite references has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "cite-references" plugin v1.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, a clean vulnerability history, and the zero attack surface from AJAX, REST API, shortcodes, and cron events are all positive indicators. Furthermore, the code signals show no dangerous functions, a complete reliance on prepared statements for SQL queries, and the presence of nonce and capability checks, all of which are excellent security practices. The low percentage of unescaped output (71%) is a minor area for improvement but not immediately critical given the absence of other significant risks.

However, the plugin does make one external HTTP request, which introduces a potential risk if the target service is compromised or malicious. While taint analysis shows no flows, this external request represents an entry point for potential data exfiltration or manipulation if the plugin doesn't handle the response securely. The limited output escaping (71%) also means there's a small window for potential cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled. Overall, the plugin demonstrates a good understanding of WordPress security principles, but the external HTTP request warrants careful consideration and review of its implementation.

Key Concerns

  • One external HTTP request detected
  • Only 71% of output properly escaped
Vulnerabilities
None known

Cite references Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Cite references Release Timeline

v1.0Current
v0.1.2
Code Analysis
Analyzed Apr 16, 2026

Cite references Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

71% escaped7 total outputs
Attack Surface

Cite references Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionload-post.phpindex.php:11
actionload-post-new.phpindex.php:12
actionadd_meta_boxesindex.php:19
actionsave_postindex.php:22
filterpost_classindex.php:139
filterthe_contentindex.php:161
Maintenance & Trust

Cite references Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedMay 14, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Cite references Alternatives

No alternatives data available yet.

Developer Profile

Cite references Developer Profile

DEJAN

4 plugins · 90 total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cite references

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
cite-option
Shortcode Output
<b><div style="border:1px solid #000000; padding:5px;">Cite this article:</b><br>
FAQ

Frequently Asked Questions about Cite references