
DOI Identifier Security & Risk Analysis
wordpress.org/plugins/doi-indentifierAdd DOI Indentifer Widget in your website used to find Research Article.
Is DOI Identifier Safe to Use in 2026?
Generally Safe
Score 85/100DOI Identifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'doi-indentifier' v1.0 plugin presents a mixed security picture. On the positive side, the plugin has no known CVEs, no recorded past vulnerabilities, and its static analysis shows a complete absence of external HTTP requests, file operations, and a complete lack of SQL injection vulnerabilities due to the exclusive use of prepared statements. The attack surface is also remarkably small, with zero AJAX handlers, REST API routes, shortcodes, and cron events, indicating a limited potential for direct exploitation of these common WordPress entry points. However, significant concerns arise from the code signals. The presence of `create_function` is a major red flag, as it can be a vector for remote code execution if user-supplied data is passed to it without proper sanitization. Furthermore, a critical weakness is the complete lack of output escaping, meaning any data outputted by the plugin could be vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks is also worrying, as these are fundamental security mechanisms in WordPress for preventing CSRF attacks and ensuring authorized actions.
Key Concerns
- Dangerous function `create_function` found
- 0% of outputs properly escaped
- No nonce checks
- No capability checks
DOI Identifier Security Vulnerabilities
DOI Identifier Code Analysis
Dangerous Functions Found
Output Escaping
DOI Identifier Attack Surface
WordPress Hooks 1
Maintenance & Trust
DOI Identifier Maintenance & Trust
Maintenance Signals
Community Trust
DOI Identifier Alternatives
DOI Creator
doi-creator
Genearate and register DOIs automatically on DataCite for every new post.
LiveJournal Importer
livejournal-importer
Import posts and comments from LiveJournal.
WP Calameo
wp-calameo
This plugin allows to embed Calaméo publications in blog posts. Copy the WordPress embed code and paste it into your post.
Content Update Scheduler
content-update-scheduler
Schedule content updates for any WordPress page or post type.
Issues and Series for Newspapers, Magazines, Publishers, Writers
organize-series
PublishPress Series is the publishing plugin that allows you to organize posts into issues or series. This is ideal for magazines, newspapers, writers …
DOI Identifier Developer Profile
3 plugins · 40 total installs
How We Detect DOI Identifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/doi-indentifier/style.cssdoi-indentifier/style.css?ver=HTML / DOM Fingerprints
doiidentifierid="resolveID"id="nameID"