
DOGO Content Widget Security & Risk Analysis
wordpress.org/plugins/dogo-content-widgetA widget to display thumbnails and titles of the latest DOGOnews, DOGObooks, and DOGOmovies reviews via RSS.
Is DOGO Content Widget Safe to Use in 2026?
Generally Safe
Score 85/100DOGO Content Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dogo-content-widget" v1.1 plugin exhibits a mixed security posture. On the positive side, it has no known vulnerabilities and no untrusted data flows identified in taint analysis. All SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are good security practices. However, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a major red flag, as it can lead to arbitrary code execution if user-supplied input is used within it without strict sanitization. Furthermore, a very low percentage of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks across its entry points, particularly the shortcodes, means that actions triggered by these shortcodes are not adequately protected against CSRF attacks or unauthorized access. While the vulnerability history is clean, this does not negate the immediate risks identified in the code itself.
Key Concerns
- Dangerous function 'create_function' used
- Very low output escaping percentage
- Missing nonce checks
- Missing capability checks
DOGO Content Widget Security Vulnerabilities
DOGO Content Widget Code Analysis
Dangerous Functions Found
Output Escaping
DOGO Content Widget Attack Surface
Shortcodes 3
WordPress Hooks 5
Maintenance & Trust
DOGO Content Widget Maintenance & Trust
Maintenance Signals
Community Trust
DOGO Content Widget Alternatives
No alternatives data available yet.
DOGO Content Widget Developer Profile
1 plugin · 10 total installs
How We Detect DOGO Content Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dogo-content-widget/style.cssdogo-content-widget/style.css?ver=HTML / DOM Fingerprints
dogoRecommendationWidgetContentdogoWidget-horizontaldogoWidget-verticaldogoRecommendationdogoImageContainercls29hcls303img+3 moredata-dogo-content-widget-type