
Credibility Security & Risk Analysis
wordpress.org/plugins/credibilityCredibility allows you to easily add footnotes to your posts.
Is Credibility Safe to Use in 2026?
Generally Safe
Score 85/100Credibility has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'credibility' plugin v1.22 exhibits a generally strong security posture based on the provided static analysis. The complete absence of identified CVEs in its history is a significant positive indicator, suggesting a history of responsible development and patching if any issues did arise. Furthermore, the code analysis reveals a clean slate regarding dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests. The presence of capability checks also indicates an effort to enforce user permissions.
However, there are areas for improvement that present minor risks. The output escaping rate is low (20%), meaning a significant portion of output is not properly sanitized. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. Additionally, the lack of any identified nonce checks across the identified entry points (though there are zero entry points) is a notable absence in typical WordPress security best practices. While the current attack surface is zero, this could become a concern if new functionalities are added without proper security considerations.
In conclusion, 'credibility' v1.22 appears to be a secure plugin with a clean vulnerability history. Its strengths lie in its lack of known exploits and its secure handling of database queries. The primary weakness is the insufficient output escaping, which warrants attention. The absence of nonce checks is a missed opportunity for robust security, though less critical given the current zero attack surface.
Key Concerns
- Low output escaping rate
- No nonce checks implemented
Credibility Security Vulnerabilities
Credibility Release Timeline
Credibility Code Analysis
Bundled Libraries
Output Escaping
Credibility Attack Surface
WordPress Hooks 10
Maintenance & Trust
Credibility Maintenance & Trust
Maintenance Signals
Community Trust
Credibility Alternatives
WooCommerce Analytics
woocommerce-analytics
Boost sales and maximize ROI with WooCommerce Analytics. Access order attribution data to optimize performance and drive business growth effectively.
Easy Footnotes
easy-footnotes
Easy Footnotes lets you quickly and easily add footnotes throughout your WordPress posts using a simple shortcode in the text editor.
Modern Footnotes
modern-footnotes
Add inline footnotes to your posts. On desktop, the footnotes will appear as tooltips. On mobile, the footnote will expand beneath the text.
CallTrackingMetrics
call-tracking-metrics
CallTrackingMetrics integrates with your WordPress site to provide powerful call tracking and attribution.
Image Source Control Lite – Show Image Credits and Captions
image-source-control-isc
Show image credits, image captions, and copyrights. Manage image sources and warn if they are missing. The original plugin since 2012.
Credibility Developer Profile
5 plugins · 50 total installs
How We Detect Credibility
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/credibility/credibility.css/wp-content/plugins/credibility/credibility-button.jscredibility/style.css?ver=credibility.css?ver=HTML / DOM Fingerprints
credibility-footnotesreturn-linkcredibility-footnoteattributionid="note-id="return-note-credButton<div class='credibility-footnotes'>