Custom Database Applications by Caspio Security & Risk Analysis

wordpress.org/plugins/custom-database-applications-by-caspio

Enables shortcodes for embedded deployment of Caspio database applications.

500 active installs v2.1 PHP + WP 3.0+ Updated Sep 7, 2022
bridgecaspiodatapagedeploymentseo
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEMar 31, 2025
Safety Verdict

Is Custom Database Applications by Caspio Safe to Use in 2026?

Use With Caution

Score 64/100

Custom Database Applications by Caspio has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Mar 31, 2025Updated 3yr ago
Risk Assessment

The Custom Database Applications by Caspio plugin v2.1 exhibits a generally good security posture regarding its direct code implementation. The absence of dangerous functions, its consistent use of prepared statements for all SQL queries, and a high percentage of properly escaped output are strong indicators of responsible coding practices. The limited attack surface, with only one shortcode and no AJAX handlers or REST API routes without checks, further contributes to its security. However, significant concerns arise from its vulnerability history and specific code signals. The presence of one unpatched medium severity CVE, specifically a Cross-site Scripting (XSS) vulnerability, represents a direct and current threat that could be exploited by attackers. Furthermore, the complete lack of nonce checks and capability checks, especially given file operations and external HTTP requests, opens the door for potential privilege escalation or unauthorized actions if an attacker can craft malicious input. The absence of taint analysis results is a minor weakness, as it limits visibility into potential data flow vulnerabilities.

While the plugin's developers have clearly prioritized secure SQL handling and output escaping, the unaddressed XSS vulnerability is a critical flaw that negates much of this good work. The reliance on external systems for security checks like nonces and capabilities, which are entirely absent in this plugin, is a major oversight. This plugin is moderately risky due to the unpatched XSS vulnerability and the lack of critical security checks, despite its otherwise clean static analysis. It is crucial for users to address the outstanding CVE immediately, and ideally, for the plugin to implement proper nonce and capability checks to bolster its overall security.

Key Concerns

  • Unpatched medium severity CVE (XSS)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
1

Custom Database Applications by Caspio Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31559medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Custom Database Applications by Caspio <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 31, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Custom Database Applications by Caspio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

95% escaped19 total outputs
Attack Surface

Custom Database Applications by Caspio Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[caspio] classes\class-datapage-loader.php:14
WordPress Hooks 1
actioninitclasses\class-datapage-loader.php:15
Maintenance & Trust

Custom Database Applications by Caspio Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 7, 2022
PHP min version
Downloads15K

Community Trust

Rating100/100
Number of ratings2
Active installs500
Developer Profile

Custom Database Applications by Caspio Developer Profile

Caspio Bridge

1 plugin · 500 total installs

69
trust score
Avg Security Score
64/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Database Applications by Caspio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
custom-database-applications-by-caspio/css/style.css?ver=custom-database-applications-by-caspio/js/script.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[caspio<iframesrc="https://cbfs.caspio.com/datapage/
FAQ

Frequently Asked Questions about Custom Database Applications by Caspio