
DICOM Support Security & Risk Analysis
wordpress.org/plugins/dicom-supportAdds DICOM (standard for medical image format) support to Wordpress!
Is DICOM Support Safe to Use in 2026?
Generally Safe
Score 91/100DICOM Support has a strong security track record. Known vulnerabilities have been patched promptly.
The 'dicom-support' plugin v0.10.7 exhibits a mixed security posture. On the positive side, the static analysis reveals adherence to several good security practices, including 100% proper output escaping, 100% prepared statement usage for SQL queries, and no identified dangerous functions, file operations, or external HTTP requests. The attack surface is also minimal, with only one shortcode and no AJAX handlers or REST API routes found without authentication checks. Taint analysis also shows no critical or high severity flows, indicating that data is generally handled safely.
However, a significant concern arises from the vulnerability history. The plugin has a known medium severity CVE related to Cross-Site Scripting, which was last patched on March 24, 2025. While this specific vulnerability is marked as patched, the existence of an XSS vulnerability, even a medium one, suggests potential weaknesses in input sanitization or output encoding in certain contexts not fully captured by the static analysis. The absence of nonce checks and capability checks on any entry points is a notable omission, especially for the shortcode, as it leaves this entry point potentially vulnerable to unauthorized or unintended execution if malicious data is passed to it.
In conclusion, while the plugin demonstrates strong internal coding practices regarding SQL and output escaping, the historical XSS vulnerability and the lack of robust authentication checks on its single entry point are points of concern. Users should ensure they are on the latest patched version to mitigate known XSS risks and remain vigilant about any future updates that address potential authorization bypasses for the shortcode.
Key Concerns
- Medium severity vulnerability (XSS)
- No nonce checks on entry points
- No capability checks on entry points
DICOM Support Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
DICOM Support <= 0.10.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
DICOM Support Code Analysis
Output Escaping
DICOM Support Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
DICOM Support Maintenance & Trust
Maintenance Signals
Community Trust
DICOM Support Alternatives
Modernizr for WordPress
modernizr
This plugin adds the Modernizr to your WordPress installation.
HTML5 Video Player for WordPress
wp-video-html5-video-player
Embed MP4, M4V, OGG, Youtube, WebM, FLV, HLS, M3u8 videos in your post or page using HTML5. Self-hosted or CDN hosted responsive HTML5 Video player.
Interactive UK Map
interactive-uk-map
Free WordPress plugin for embedding an interactive United Kingdom map with clickable regions. Easy to install and configure.
Responsive P5JS for WP
responsive-p5js-for-wp
Embed your P5JS sketches in posts and pages in a responsive way
Interactive Australia Map
interactive-australia-map
Free WordPress plugin for embedding an interactive Australia map with clickable states. Easy to install and configure.
DICOM Support Developer Profile
1 plugin · 80 total installs
How We Detect DICOM Support
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dicom-support/public/appgui.js/wp-content/plugins/dicom-support/public/applauncher.js/wp-content/plugins/dicom-support/public/style.css/wp-content/plugins/dicom-support/node_modules/konva/konva.min.js/wp-content/plugins/dicom-support/node_modules/jszip/dist/jszip.min.js/wp-content/plugins/dicom-support/node_modules/dwv/decoders/dwv/rle.js/wp-content/plugins/dicom-support/node_modules/dwv/decoders/pdfjs/arithmetic_decoder.js/wp-content/plugins/dicom-support/node_modules/dwv/decoders/pdfjs/util.js+4 moreHTML / DOM Fingerprints
dwvtoolbarlayerGroup<!-- Main container div --><!-- Toolbar --><!-- Layer Container -->id="dwv-id="toolbar-id="layerGroup-startApp<div id="dwv-<div id="toolbar-<div id="layerGroup-