
CrunchBase API Widget Security & Risk Analysis
wordpress.org/plugins/crunchbase-api-widgetAdd CrunchBase company details widgets to your posts , pages and blog widgets
Is CrunchBase API Widget Safe to Use in 2026?
Generally Safe
Score 85/100CrunchBase API Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "crunchbase-api-widget" v1.0 plugin exhibits a generally good security posture with no recorded vulnerabilities and a clean taint analysis. The absence of dangerous functions, external HTTP requests, and raw SQL queries, coupled with the use of prepared statements, are strong indicators of secure coding practices in these areas. The plugin also correctly implements capability checks for its single entry point.
However, a significant concern arises from the complete lack of output escaping for all identified output points. This means that any data rendered by the widget could potentially be manipulated by an attacker to inject malicious code, leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks, while not directly linked to an identified vulnerability in this analysis, is a common security control that is missing and could be exploited in conjunction with other weaknesses or in future versions if new entry points are introduced.
In conclusion, while the plugin demonstrates a solid foundation in areas like SQL handling and capability checks, the widespread lack of output escaping presents a critical security risk that overshadows its strengths. The vulnerability history being clean is a positive sign, but it does not mitigate the immediate threat posed by unescaped output.
Key Concerns
- 0% of outputs properly escaped
- 0 nonce checks implemented
CrunchBase API Widget Security Vulnerabilities
CrunchBase API Widget Code Analysis
Output Escaping
CrunchBase API Widget Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
CrunchBase API Widget Maintenance & Trust
Maintenance Signals
Community Trust
CrunchBase API Widget Alternatives
MAS Companies For WP Job Manager
mas-wp-job-manager-company
MAS Companies For WP Job Manager is a free plugin that allow you to manage companies from the WordPress admin panel, and allow employers to post their …
MAS Company Reviews For WP Job Manager
mas-wp-job-manager-company-reviews
MAS Company Reviews For WP Job Manager is a free plugin that allow you to review companies in multiple review categories and controlling star count.
WP Job Manager
wp-job-manager
Create a careers page for your company website, or build a public job board for your community.
Bold Timeline Lite
bold-timeline-lite
Bold Timeline Lite – WordPress Timeline Plugin
Timeline Express
timeline-express
Timeline Express creates a beautiful vertical animated and responsive timeline of posts, in chronological order.
CrunchBase API Widget Developer Profile
3 plugins · 4K total installs
How We Detect CrunchBase API Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
cb_shortcodeerrorMessageerrorname="cbapi-options-submit"id="cbapi-options-submit"name="cbapi-title"id="cbapi-title"name="cbapi-cbapikey"id="cbapi-cbapikey"+4 more<div class="cb_shortcode">Founded on Email Id: Category: