
Dave’s Whizmatronic Widgulating Calibrational Scribometer Security & Risk Analysis
wordpress.org/plugins/daves-whizmatronic-widgulating-calibrational-scribometerThe Scribometer allows writers to track and display their writing progress in their sidebar.
Is Dave’s Whizmatronic Widgulating Calibrational Scribometer Safe to Use in 2026?
Generally Safe
Score 85/100Dave’s Whizmatronic Widgulating Calibrational Scribometer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "daves-whizmatronic-widgulating-calibrational-scribometer" v0.3.0 exhibits a mixed security posture. On the positive side, the absence of known CVEs and a clean vulnerability history are excellent indicators. The plugin also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a complete lack of file operations or external HTTP requests, which reduces potential attack vectors. However, the static analysis reveals significant concerns. The presence of the `create_function` dangerous function is a notable risk, as it can lead to code injection vulnerabilities if not handled with extreme care, especially in conjunction with user-supplied input. Furthermore, a very low percentage (17%) of output escaping indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-controlled data is likely being rendered without proper sanitization. The lack of nonce and capability checks across all entry points is also a critical oversight, leaving the plugin susceptible to various attacks that can exploit unintended actions.
Key Concerns
- Low percentage of output escaping (17%)
- Presence of dangerous function 'create_function'
- No nonce checks on entry points
- No capability checks on entry points
Dave’s Whizmatronic Widgulating Calibrational Scribometer Security Vulnerabilities
Dave’s Whizmatronic Widgulating Calibrational Scribometer Release Timeline
Dave’s Whizmatronic Widgulating Calibrational Scribometer Code Analysis
Dangerous Functions Found
Output Escaping
Dave’s Whizmatronic Widgulating Calibrational Scribometer Attack Surface
WordPress Hooks 1
Maintenance & Trust
Dave’s Whizmatronic Widgulating Calibrational Scribometer Maintenance & Trust
Maintenance Signals
Community Trust
Dave’s Whizmatronic Widgulating Calibrational Scribometer Alternatives
Ultimeter
ultimeter
Ultimeter - the Ultimate Progress and Goals Meter
Author WIP Progress Bar
author-work-in-progress-bar
Tested up to 6.7.1 The WIP Progress Bar plugin allows writers and authors to display beautiful progress bars on their WordPress websites via a Widget …
Pretty Simple Progress meter
pretty-simple-progress-meter
Pretty Simply Progress meter is a clean and fun way to share your tracked progress on everything!
ProgPress
progpress
Easily insert progress meters into your content and/or sidebars.
WC Weight Meter
wc-weight-meter
A WooCommerce weight meter plugin that allows customers to view the total weight of their cart in real-time with a customizable progress bar.
Dave’s Whizmatronic Widgulating Calibrational Scribometer Developer Profile
1 plugin · 20 total installs
How We Detect Dave’s Whizmatronic Widgulating Calibrational Scribometer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
scribometerscribometer-bodyscribometer-script-titlescribometer-borderscribometer-barscribometer-draftscribometer-progressscribometer-link<!--Title of Work--><!--Progress Bar--><!--optional text--><!--END .scribometer_bar-->+3 moreid="scribometer"id="scribometer-body"class="scribometer-script-title"class="scribometer-border"class="scribometer-bar"class="scribometer-draft"+2 more<p class="scribometer-link">Powered by <a href="http://davidanaxagoras.com/whizmatronic/">Dave's Scribometer</a></p>