Corner Bracket Lover Security & Risk Analysis

wordpress.org/plugins/corner-bracket-lover

Corner Bracket Lover converts all curly quotation marks (“” and ‘’) in your posts to traditional corner brackets (「」 and 『』).

10 active installs v1.2.10 PHP + WP 1.5+ Updated Aug 11, 2021
characterchinachinesecommentcomments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Corner Bracket Lover Safe to Use in 2026?

Generally Safe

Score 85/100

Corner Bracket Lover has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "corner-bracket-lover" plugin v1.2.10 demonstrates a generally positive security posture based on the provided static analysis. There are no identified entry points for external interaction such as AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks. Furthermore, the code signals indicate a complete absence of dangerous functions, file operations, and external HTTP requests, which significantly reduces the potential for common attack vectors. The plugin also adheres to secure database practices by exclusively using prepared statements for its SQL queries.

However, a critical concern arises from the output escaping analysis. With one total output identified and 0% properly escaped, this represents a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the user interface that originates from the plugin could be manipulated by an attacker to inject malicious scripts, leading to session hijacking or other client-side attacks. The lack of explicit capability checks and nonce checks, while not directly flagged as an issue due to the absence of entry points, means that if any entry points were to be introduced in future versions without proper checks, the plugin would be susceptible.

The vulnerability history is clean, with no recorded CVEs. This, combined with the absence of taint analysis findings and a clean bill of health regarding dangerous functions and SQL practices, suggests that the plugin author has been diligent in addressing security in past development. Despite the strong foundation and clean history, the glaring issue of unescaped output remains a primary security weakness that requires immediate attention to mitigate the risk of XSS attacks.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Corner Bracket Lover Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Corner Bracket Lover Release Timeline

v1.2.10Current
v1.2.8
v1.2.7
v1.2.6
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.2
v1.1.1
v1.1.0
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Corner Bracket Lover Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Corner Bracket Lover Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actioninitcorner-bracket-lover.php:35
actionadmin_initcorner-bracket-lover.php:36
actionadmin_menucorner-bracket-lover.php:37
actionplugins_loadedcorner-bracket-lover.php:38
filterplugin_action_linkscorner-bracket-lover.php:39
actionactivated_plugincorner-bracket-lover.php:41
actionshutdowncorner-bracket-lover.php:46
filterthe_contentcorner-bracket-lover.php:220
filterbbp_get_topic_contentcorner-bracket-lover.php:224
filterbbp_get_reply_contentcorner-bracket-lover.php:225
filterthe_excerptcorner-bracket-lover.php:229
filterthe_titlecorner-bracket-lover.php:232
filtercomment_textcorner-bracket-lover.php:235
filterget_comment_authorcorner-bracket-lover.php:238
filterbloginfocorner-bracket-lover.php:241
filtercategory_descriptioncorner-bracket-lover.php:244
filterterm_links-post_tagcorner-bracket-lover.php:247
filterwp_tag_cloudcorner-bracket-lover.php:250
Maintenance & Trust

Corner Bracket Lover Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedAug 11, 2021
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Corner Bracket Lover Developer Profile

Sparanoid

10 plugins · 4K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Corner Bracket Lover

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Corner Bracket Lover