
Client Showcase Security & Risk Analysis
wordpress.org/plugins/client-showcaseDisplay your Clients with pride. This plugin displays your client's logo in a page, post using a shortcode or use the custom widget.
Is Client Showcase Safe to Use in 2026?
Use With Caution
Score 64/100Client Showcase has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The client-showcase plugin v1.2.0 exhibits a concerning security posture due to a significant lack of proper input validation and output escaping, coupled with a known unpatched vulnerability. The static analysis reveals an unprotected AJAX handler, which presents a direct entry point for attackers. The high percentage of unsanitized output (96%) is particularly alarming, suggesting a strong likelihood of Cross-Site Scripting (XSS) vulnerabilities. This is further corroborated by the vulnerability history, which shows a medium severity XSS vulnerability from April 2025 that remains unpatched, indicating a pattern of insecure coding practices and a lack of diligent security patching. While the plugin doesn't use dangerous functions, perform file operations, or make external HTTP requests, these strengths are overshadowed by the critical weaknesses in handling user input and securing entry points. The absence of nonce and capability checks on the identified AJAX handler is a significant oversight, leaving the application vulnerable to various attacks.
Key Concerns
- Unprotected AJAX handler
- High percentage of unsanitized output
- Unpatched medium severity CVE
- Flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
- Low percentage of prepared SQL statements
Client Showcase Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Client Showcase <= 1.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Client Showcase Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Client Showcase Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Client Showcase Maintenance & Trust
Maintenance Signals
Community Trust
Client Showcase Alternatives
Canto Clients
canto-clients
Canto Clients simple and effective client logo shortcode.
Contact widget – Ocl.to
ocl-widget
Generate your own contact widget and paste it to your Wordpress page. Gather information about clients and automatically transfer it to your Ocl CRM s …
WP Help
wp-help
Site operators can create detailed, hierarchical documentation for the site's authors, editors, and contributors, viewable in the WordPress admin …
CPO Content Types
cpo-content-types
Add support for special content types in your website, such as a portfolio, features, and slides.
Guaranteed Reviews Company (Société des Avis Garantis)
woo-guaranteed-reviews-company
Collect and display product and website reviews through Guaranteed Reviews Company / Société des Avis Garantis.
Client Showcase Developer Profile
3 plugins · 360 total installs
How We Detect Client Showcase
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/client-showcase/css/client-showcase-public-styles.cssHTML / DOM Fingerprints
client_showcase_widget_sizeclient_url<ul id="listStyle"><liid="listStyle">