Custom QR Code Generator Security & Risk Analysis

wordpress.org/plugins/custom-qr-code-generator

Easily generate customizable QR codes for websites, products, and events with this user-friendly WordPress plugin.

30 active installs v1.0.3 PHP 7.4+ WP 5.6+ Updated Dec 30, 2025
qr-codeqr-code-generatorqr-code-in-page-postqr-code-shortcodesqr-code-wordpress-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom QR Code Generator Safe to Use in 2026?

Generally Safe

Score 100/100

Custom QR Code Generator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The custom-qr-code-generator plugin v1.0.3 presents a mixed security posture. On the positive side, the plugin exhibits strong adherence to secure coding practices regarding SQL queries, with nearly all using prepared statements, and a high percentage of output being properly escaped. It also demonstrates a good understanding of nonces and avoids dangerous functions. The absence of any recorded CVEs is a significant strength, suggesting a history of responsible development or a lack of past exploitation. However, the plugin has a notable weakness in its attack surface. Four out of five identified entry points (AJAX handlers and a REST API route) lack proper authentication or permission checks. This creates a significant opening for unauthorized access and potential manipulation of plugin functionalities.

Further concerns arise from the taint analysis, which identified two flows with unsanitized paths, both classified as high severity. While no critical vulnerabilities were flagged, these high-severity flows, coupled with the unprotected entry points, indicate a potential for serious security issues if exploited. The bundled 'dompdf' library is also a point to monitor, as outdated bundled libraries can sometimes harbor unpatched vulnerabilities, though no direct evidence of this is present in the provided data. In conclusion, while the plugin benefits from secure SQL and output handling and a clean CVE history, the substantial number of unprotected entry points and the presence of high-severity taint flows are significant security concerns that require immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Unprotected REST API route
  • High severity unsanitized paths
  • Bundled library (dompdf)
Vulnerabilities
None known

Custom QR Code Generator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom QR Code Generator Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
82 prepared
Unescaped Output
21
269 escaped
Nonce Checks
13
Capability Checks
0
File Operations
4
External Requests
2
Bundled Libraries
1

Bundled Libraries

dompdf

SQL Query Safety

99% prepared83 total queries

Output Escaping

93% escaped290 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

11 flows2 with unsanitized paths
cqrc_get_embed_code_callback (admin\class-cqrc-generator-admin.php:2198)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Custom QR Code Generator Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 3

authwp_ajax_cqrc_handle_qrurl_insert_recordincludes\class-cqrc-generator.php:160
authwp_ajax_cqrc_check_animated_webpincludes\class-cqrc-generator.php:161
authwp_ajax_cqrc_get_embed_code_callbackincludes\class-cqrc-generator.php:162

REST API Routes 1

POST/wp-json/cqrc/v1/get-qr-code/public\class-cqrc-generator-public.php:300

Shortcodes 1

[cqrc_gen_qrcode_view] public\class-cqrc-generator-public.php:166
WordPress Hooks 15
filterintermediate_image_sizes_advancedadmin\class-cqrc-generator-admin.php:2025
actioninitcustom-qr-code-generator.php:76
actioninitincludes\class-cqrc-generator.php:142
actionadmin_menuincludes\class-cqrc-generator.php:155
actionadmin_enqueue_scriptsincludes\class-cqrc-generator.php:156
actionadmin_enqueue_scriptsincludes\class-cqrc-generator.php:157
actionadmin_initincludes\class-cqrc-generator.php:158
actionadmin_initincludes\class-cqrc-generator.php:159
actioninitincludes\class-cqrc-generator.php:175
actioninitincludes\class-cqrc-generator.php:176
actionwp_enqueue_scriptsincludes\class-cqrc-generator.php:177
actiontemplate_includeincludes\class-cqrc-generator.php:178
filterquery_varsincludes\class-cqrc-generator.php:179
actionrest_api_initincludes\class-cqrc-generator.php:180
filterpre_get_document_titleincludes\qrcode-functions.php:171
Maintenance & Trust

Custom QR Code Generator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 30, 2025
PHP min version7.4
Downloads642

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Custom QR Code Generator Developer Profile

World Web Technology

4 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Custom QR Code Generator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-qr-code-generator/admin/assets/css/cqrc-generator-admin.css/wp-content/plugins/custom-qr-code-generator/admin/assets/css/cqrc-font-awesome.css/wp-content/plugins/custom-qr-code-generator/admin/assets/js/cqrc-generator-admin.js
Script Paths
/wp-content/plugins/custom-qr-code-generator/admin/assets/js/cqrc-generator-admin.js
Version Parameters
custom-qr-code-generator/admin/assets/css/cqrc-generator-admin.css?ver=custom-qr-code-generator/admin/assets/css/cqrc-font-awesome.css?ver=custom-qr-code-generator/admin/assets/js/cqrc-generator-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
cqrc-generator-admin-container
HTML Comments
<!-- Cqrc_Generator_Admin --><!-- wp_enqueue_script: cqrc-generator-admin -->
Data Attributes
data-plugin-logo-image-pathdata-plugin-frame-image-pathdata-plugin-template-image-pathdata-plugin-eye-frame-image-pathdata-plugin-eye-balls-image-path
JS Globals
wwtQrCodeGenerator
FAQ

Frequently Asked Questions about Custom QR Code Generator