
Classy Security & Risk Analysis
wordpress.org/plugins/classyA tool used to integrate Classy.org's API into easily accessible shortcodes
Is Classy Safe to Use in 2026?
Generally Safe
Score 85/100Classy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'classy' v1.2.3 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, file operations, or SQL queries that are not using prepared statements. The absence of known vulnerabilities in its history is also a strong indicator of good development practices. However, several areas raise significant concerns. The plugin relies entirely on shortcodes for its attack surface, which is quite large with 18 entry points. Crucially, there are no nonce checks or capability checks present on these shortcodes, meaning any authenticated user could potentially trigger these functions, and there's no protection against CSRF attacks. Furthermore, only 20% of output is properly escaped, presenting a risk of cross-site scripting (XSS) vulnerabilities through the shortcode outputs. The substantial number of external HTTP requests (30) also introduces potential risks if the targets of these requests are compromised or if the plugin doesn't validate the responses adequately. While taint analysis shows no immediate critical or high severity flows, the lack of proper output escaping and authentication on the primary attack surface leaves it vulnerable to attack.
Key Concerns
- No nonce checks on shortcodes
- No capability checks on shortcodes
- Low output escaping percentage (20%)
- Large attack surface via shortcodes
- Significant number of external HTTP requests (30)
Classy Security Vulnerabilities
Classy Release Timeline
Classy Code Analysis
Output Escaping
Classy Attack Surface
Shortcodes 18
WordPress Hooks 18
Maintenance & Trust
Classy Maintenance & Trust
Maintenance Signals
Community Trust
Classy Alternatives
Beans Simple Shortcodes
beans-simple-shortcodes
A useful companion tool for theme development with the Beans Framework. Provides a library of Shortcodes that can more easily display information abo …
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
Meta pixel for WordPress
official-facebook-pixel
Grow your business with Meta for WordPress!
WooCommerce Legacy REST API
woocommerce-legacy-rest-api
The WooCommerce Legacy REST API, which is now part of WooCommerce itself but will be removed in WooCommerce 9.0.
Classy Developer Profile
2 plugins · 20 total installs
How We Detect Classy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/classy/admin/css/classy-admin.css/wp-content/plugins/classy/admin/js/classy-admin.js/wp-content/plugins/classy/admin/js/classy-admin.jsclassy-admin.css?ver=classy-admin.js?ver=HTML / DOM Fingerprints
classy-admin-wrap<!-- This file is part of the classy Plugin. --><!-- Provides the admin-specific functionality for the plugin. -->data-tokendata-cidclassy