
DeadTrees Security & Risk Analysis
wordpress.org/plugins/dead-treesShare the books you've read with your readers, family, & friends. Never again receive a book you've already read as a gift!
Is DeadTrees Safe to Use in 2026?
Generally Safe
Score 85/100DeadTrees has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dead-trees" v1.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, even historically, is a very positive indicator. The plugin also demonstrates good practices by using prepared statements for all SQL queries and implementing nonce and capability checks, albeit only once each. The minimal attack surface with no exposed AJAX, REST API, or shortcodes further contributes to its safety. However, a significant concern lies in the output escaping, with only 54% of outputs being properly escaped. This means a considerable portion of dynamic content rendered by the plugin could be vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not sufficiently sanitized before being outputted. The presence of file operations and external HTTP requests, while not inherently insecure, represent potential vectors that would require further scrutiny in a deeper analysis, especially given the partial output escaping.
Key Concerns
- Partial output escaping identified
DeadTrees Security Vulnerabilities
DeadTrees Code Analysis
Output Escaping
DeadTrees Attack Surface
WordPress Hooks 9
Maintenance & Trust
DeadTrees Maintenance & Trust
Maintenance Signals
Community Trust
DeadTrees Alternatives
BNC BiblioShare
bnc-biblioshare
Displays a book's cover image, title, author, and other book data from BiblioShare
Bestseller Lists from the New York Times
bestseller-lists-from-new-york-times
Integrate bestseller lists from the New York Times into your own site with a user-friendly interface.
My Google Books Library
my-google-books-library
A simple plugin with a widget and [shortcode] that displays any number of your Google Books bookshelves including custom made bookshelves.
Library Bookshelves
library-bookshelves
Create bookshelves that link to your library catalog. Use shortcodes to display book covers in carousels.
Library Management System
library-management-system
Library Management System is a WordPress plugin that helps schools and colleges manage libraries, bookcases, sections, categories, and users.
DeadTrees Developer Profile
2 plugins · 20 total installs
How We Detect DeadTrees
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dead-trees/css/deadtrees.css/wp-content/plugins/dead-trees/js/deadtrees.js/wp-content/plugins/dead-trees/js/deadtrees.jsdead-trees/css/deadtrees.css?ver=dead-trees/js/deadtrees.js?ver=HTML / DOM Fingerprints
<!-- Dead Trees Start --><!-- Dead Trees End --><!-- The Dead Trees Plugin provides this HTML for the Amazon Affiliate Link--><!-- Dead Trees Plugin: If no data found, display message -->+1 moredata-dt-amazon-urldata-dt-asindata-dt-descriptiondata-dt-cover-urldata-dt-titlewindow.deadtreesvar dt_opts<div class="dt-book-wrapper"><div class="dt-book-info"><div class="dt-book-cover"><div class="dt-book-details">