Clker.com clip art Security & Risk Analysis

wordpress.org/plugins/clkercom-clip-art

Search and add Clker.com clip art images to your posts.

10 active installs v1.2.3 PHP + WP 2.5+ Updated Nov 7, 2009
clip-artclipartgraphicspublic-domainroyalty-free
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Clker.com clip art Safe to Use in 2026?

Generally Safe

Score 85/100

Clker.com clip art has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "clkercom-clip-art" plugin v1.2.3 exhibits a strong security posture in terms of its attack surface and vulnerability history. The static analysis reveals zero AJAX handlers, REST API routes, shortcodes, or cron events, indicating a very limited entry point for potential attacks. Furthermore, the absence of any known CVEs or recorded past vulnerabilities suggests a well-maintained and secure plugin. The code also demonstrates good practices with 100% of SQL queries using prepared statements and only two capability checks, implying careful handling of data and user permissions where they are relevant.

However, a significant concern arises from the output escaping analysis. With one total output and 0% properly escaped, this presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin that is not properly escaped can be exploited by attackers to inject malicious scripts, potentially leading to session hijacking, defacement, or other harmful actions. The single file operation, while not inherently a risk, warrants attention if it involves user-supplied input or is performed in a sensitive location.

In conclusion, while the plugin is commendably free of known vulnerabilities and has a minimal attack surface, the lack of output escaping is a critical weakness. Addressing this single vulnerability point would significantly enhance the plugin's overall security. The plugin's strengths lie in its controlled entry points and robust SQL handling, but the unescaped output represents a tangible and potentially exploitable flaw.

Key Concerns

  • 0% properly escaped output
Vulnerabilities
None known

Clker.com clip art Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Clker.com clip art Release Timeline

v1.2.1
v1.2
v1.1
v1.0
Code Analysis
Analyzed Mar 17, 2026

Clker.com clip art Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Clker.com clip art Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtermce_external_pluginsclker.php:35
filtermce_buttonsclker.php:36
actioninitclker.php:52
Maintenance & Trust

Clker.com clip art Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedNov 7, 2009
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Clker.com clip art Developer Profile

mibrahim74

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Clker.com clip art

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clkercom-clip-art/mce/editor_plugin.js
Script Paths
../../../wp-content/plugins/clkercom-clip-art/mce/editor_plugin.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Clker.com clip art