
Clicface Organi Security & Risk Analysis
wordpress.org/plugins/clicface-organiCreate Org Charts easily in WordPress. A flexible and lightweight WordPress plugin, working with Clicface Trombi.
Is Clicface Organi Safe to Use in 2026?
Generally Safe
Score 92/100Clicface Organi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The clicface-organi plugin v2.08 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests, which are all excellent security practices. The presence of nonce and capability checks on a majority of entry points also suggests a degree of security awareness in development. However, a significant concern arises from the output escaping. With only 37% of outputs being properly escaped, this leaves a substantial portion vulnerable to cross-site scripting (XSS) attacks. While the taint analysis shows no critical or high severity flows, this is likely due to the limited scope or absence of complex data flows in the analyzed code, rather than a guarantee of absolute safety, especially given the unescaped output.
The plugin's vulnerability history is a clear strength, showing zero known CVEs across all severity levels and no recorded vulnerabilities. This suggests a history of stable and secure development. However, this should not be interpreted as a guarantee of future security, particularly when combined with the identified output escaping issues. The lack of historical vulnerabilities might be due to the plugin's niche nature, limited usage, or simply a lack of in-depth security auditing in the past. The plugin's attack surface is relatively small, with two identified entry points, both of which appear to have some level of protection. The primary weakness lies in the inadequate output sanitization, which presents a tangible risk for XSS vulnerabilities that could be exploited if malicious data is processed and displayed without proper escaping.
Key Concerns
- Insufficient output escaping
Clicface Organi Security Vulnerabilities
Clicface Organi Code Analysis
Output Escaping
Clicface Organi Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 28
Maintenance & Trust
Clicface Organi Maintenance & Trust
Maintenance Signals
Community Trust
Clicface Organi Alternatives
Organization chart
organization-chart
WordPress organization chart plugin is a nice and handy tool for creating simple and nice organizational charts. If you have any suggestions about the …
Interactive Organizational Chart
interactive-organizational-chart
A complete WordPress plugin for managing and displaying interactive organizational charts with admin and editor data upload and user-friendly viewing.
MainWP Child – Securely Connects to the MainWP Dashboard to Manage Multiple Sites
mainwp-child
MainWP Child establishes a secure link between your WordPress sites and your self-hosted MainWP Dashboard, simplifying site management.
Download Manager
download-manager
This File Management & Digital Store plugin will help you to control file downloads & sell digital products from your WP site.
Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution
file-manager-advanced
Use Advanced File Manager to manage WordPress files, create archives, and build document libraries—all directly from your WordPress dashboard!
Clicface Organi Developer Profile
2 plugins · 230 total installs
How We Detect Clicface Organi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clicface-organi/css/clicface-organi-admin-styles.css/wp-content/plugins/clicface-organi/lib/jquery.jOrgChart.js/wp-content/plugins/clicface-organi/lib/clicface-organi.js/wp-content/plugins/clicface-organi/lib/clicface-organi-admin-label.js/wp-content/plugins/clicface-organi/lib/jquery.jOrgChart.js/wp-content/plugins/clicface-organi/lib/clicface-organi.js/wp-content/plugins/clicface-organi/lib/clicface-organi-admin-label.jsHTML / DOM Fingerprints
clicface-field-containerclicface-label-containerclicface-labelclicface-fieldclicface-field-listid="orgchart_title"name="orgchart_title"id="orgchart_boss"name="orgchart_boss"id="orgchart_data"name="orgchart_data"+5 morewindow.clicface_organi_settings