CrunchBase API Widget Security & Risk Analysis

wordpress.org/plugins/crunchbase-api-widget

Add CrunchBase company details widgets to your posts , pages and blog widgets

10 active installs v1.0 PHP + WP 3.3+ Updated Feb 8, 2014
companycompany-contact-informationcompany-listingcrunchbase
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CrunchBase API Widget Safe to Use in 2026?

Generally Safe

Score 85/100

CrunchBase API Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "crunchbase-api-widget" v1.0 plugin exhibits a generally good security posture with no recorded vulnerabilities and a clean taint analysis. The absence of dangerous functions, external HTTP requests, and raw SQL queries, coupled with the use of prepared statements, are strong indicators of secure coding practices in these areas. The plugin also correctly implements capability checks for its single entry point.

However, a significant concern arises from the complete lack of output escaping for all identified output points. This means that any data rendered by the widget could potentially be manipulated by an attacker to inject malicious code, leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks, while not directly linked to an identified vulnerability in this analysis, is a common security control that is missing and could be exploited in conjunction with other weaknesses or in future versions if new entry points are introduced.

In conclusion, while the plugin demonstrates a solid foundation in areas like SQL handling and capability checks, the widespread lack of output escaping presents a critical security risk that overshadows its strengths. The vulnerability history being clean is a positive sign, but it does not mitigate the immediate threat posed by unescaped output.

Key Concerns

  • 0% of outputs properly escaped
  • 0 nonce checks implemented
Vulnerabilities
None known

CrunchBase API Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CrunchBase API Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped13 total outputs
Attack Surface

CrunchBase API Widget Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cb] crunchbase.php:224
WordPress Hooks 2
actionwidgets_initcrunchbase.php:227
actionadmin_menucrunchbase.php:230
Maintenance & Trust

CrunchBase API Widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedFeb 8, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

CrunchBase API Widget Developer Profile

iteamweb

3 plugins · 4K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CrunchBase API Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
cb_shortcodeerrorMessageerror
Data Attributes
name="cbapi-options-submit"id="cbapi-options-submit"name="cbapi-title"id="cbapi-title"name="cbapi-cbapikey"id="cbapi-cbapikey"+4 more
Shortcode Output
<div class="cb_shortcode">Founded on Email Id: Category:
FAQ

Frequently Asked Questions about CrunchBase API Widget