Clicface Organi Security & Risk Analysis

wordpress.org/plugins/clicface-organi

Create Org Charts easily in WordPress. A flexible and lightweight WordPress plugin, working with Clicface Trombi.

200 active installs v2.08 PHP 5.6+ WP 4.7+ Updated Nov 12, 2024
managementmanagement-toolorg-chartorganigramorganizational-chart
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Clicface Organi Safe to Use in 2026?

Generally Safe

Score 92/100

Clicface Organi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The clicface-organi plugin v2.08 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no direct SQL queries (all use prepared statements), no file operations, and no external HTTP requests, which are all excellent security practices. The presence of nonce and capability checks on a majority of entry points also suggests a degree of security awareness in development. However, a significant concern arises from the output escaping. With only 37% of outputs being properly escaped, this leaves a substantial portion vulnerable to cross-site scripting (XSS) attacks. While the taint analysis shows no critical or high severity flows, this is likely due to the limited scope or absence of complex data flows in the analyzed code, rather than a guarantee of absolute safety, especially given the unescaped output.

The plugin's vulnerability history is a clear strength, showing zero known CVEs across all severity levels and no recorded vulnerabilities. This suggests a history of stable and secure development. However, this should not be interpreted as a guarantee of future security, particularly when combined with the identified output escaping issues. The lack of historical vulnerabilities might be due to the plugin's niche nature, limited usage, or simply a lack of in-depth security auditing in the past. The plugin's attack surface is relatively small, with two identified entry points, both of which appear to have some level of protection. The primary weakness lies in the inadequate output sanitization, which presents a tangible risk for XSS vulnerabilities that could be exploited if malicious data is processed and displayed without proper escaping.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Clicface Organi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Clicface Organi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
7 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

37% escaped19 total outputs
Attack Surface

Clicface Organi Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_my_organi_modification_submitclicface-organi.php:985

Shortcodes 1

[clicface-organi] clicface-organi.php:389
WordPress Hooks 28
actioninitclicface-organi.php:22
actionadmin_initclicface-organi.php:34
actionadmin_print_stylesclicface-organi.php:45
actioninitclicface-organi.php:53
actioninitclicface-organi.php:85
actionadd_meta_boxes_orgchartclicface-organi.php:117
actionadd_meta_boxes_orgchart-labelclicface-organi.php:164
actionnew_to_publishclicface-organi.php:229
actionauto-draft_to_publishclicface-organi.php:230
actiondraft_to_publishclicface-organi.php:231
actionpending_to_publishclicface-organi.php:232
actionnew_to_publishclicface-organi.php:242
actionauto-draft_to_publishclicface-organi.php:243
actiondraft_to_publishclicface-organi.php:244
actionpending_to_publishclicface-organi.php:245
actionsave_postclicface-organi.php:255
actionsave_postclicface-organi.php:262
actionsave_postclicface-organi.php:269
actionsave_postclicface-organi.php:283
actionsave_postclicface-organi.php:289
actionsave_postclicface-organi.php:303
actionsave_postclicface-organi.php:309
filtermanage_edit-orgchart_columnsclicface-organi.php:336
actionmanage_orgchart_posts_custom_columnclicface-organi.php:348
filtermanage_edit-orgchart-label_columnsclicface-organi.php:361
actionmanage_orgchart-label_posts_custom_columnclicface-organi.php:373
actioninitclicface-organi.php:1004
actionadmin_menuclicface-organi.php:1024
Maintenance & Trust

Clicface Organi Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 12, 2024
PHP min version5.6
Downloads26K

Community Trust

Rating52/100
Number of ratings5
Active installs200
Developer Profile

Clicface Organi Developer Profile

clicface

2 plugins · 230 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Clicface Organi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clicface-organi/css/clicface-organi-admin-styles.css/wp-content/plugins/clicface-organi/lib/jquery.jOrgChart.js/wp-content/plugins/clicface-organi/lib/clicface-organi.js/wp-content/plugins/clicface-organi/lib/clicface-organi-admin-label.js
Script Paths
/wp-content/plugins/clicface-organi/lib/jquery.jOrgChart.js/wp-content/plugins/clicface-organi/lib/clicface-organi.js/wp-content/plugins/clicface-organi/lib/clicface-organi-admin-label.js

HTML / DOM Fingerprints

CSS Classes
clicface-field-containerclicface-label-containerclicface-labelclicface-fieldclicface-field-list
Data Attributes
id="orgchart_title"name="orgchart_title"id="orgchart_boss"name="orgchart_boss"id="orgchart_data"name="orgchart_data"+5 more
JS Globals
window.clicface_organi_settings
FAQ

Frequently Asked Questions about Clicface Organi