
Dooodl Security & Risk Analysis
wordpress.org/plugins/dooodlDooodl is a fun plugin for your blog that allows your visitors to draw a little doodle and save it to your site.
Is Dooodl Safe to Use in 2026?
Mostly Safe
Score 70/100Dooodl is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The 'dooodl' v2.3.0 plugin exhibits a concerning security posture due to a significant number of unprotected entry points and a history of vulnerabilities. The static analysis reveals that 3 out of 6 total entry points, all of which are AJAX handlers, lack proper authentication checks. This is a critical oversight that could allow unauthenticated users to trigger potentially harmful actions. Furthermore, the taint analysis indicates all analyzed flows involve unsanitized paths, and while no critical or high severity issues were found, this suggests a general lack of input validation and sanitization throughout the codebase. The plugin's vulnerability history is also a major red flag, with one currently unpatched medium severity vulnerability related to Cross-Site Scripting. This, coupled with the lack of nonce checks and capability checks in the code signals, points to a pattern of insecure coding practices that have led to past security flaws. While the plugin does not appear to use dangerous functions, the raw SQL queries, the low percentage of properly escaped output, and the absence of nonce and capability checks on AJAX handlers are significant weaknesses that, when combined with the existing unpatched vulnerability and unprotected entry points, create a high-risk profile. The presence of bundled libraries like TinyMCE and Select2, while common, doesn't mitigate the fundamental security flaws.
Key Concerns
- Unprotected AJAX handlers
- All Taint Flows have unsanitized paths
- Unpatched Medium Vulnerability (XSS)
- SQL queries not fully prepared
- Low percentage of output escaping
- No nonce checks on AJAX handlers
- No capability checks found
Dooodl Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Dooodl <= 2.3.0 - Reflected Cross-Site Scripting
Dooodl Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Dooodl Attack Surface
AJAX Handlers 3
Shortcodes 3
WordPress Hooks 36
Maintenance & Trust
Dooodl Maintenance & Trust
Maintenance Signals
Community Trust
Dooodl Alternatives
Gwolle Guestbook
gwolle-gb
Gwolle Guestbook is the WordPress guestbook you've just been looking for. Beautiful and easy.
WP-ViperGB
wp-vipergb
Create a stylish and user-friendly Guestbook for your Wordpress blog. Designed to replicate the appearance and behavior of Viper Guestbook.
Guestbook Generator
guestbook-generator
Instantly generates a guestbook for Wordpress blogs based on the active theme.
Embed Google Drive
embed-google-drive
Embed a link and preview of Google Drive Documents by pasting a shared document link into the editor.
Reverse Order Comments
reverse-order-comments
Allows to display the comments in reverse order. Latest comment first, oldest last.
Dooodl Developer Profile
1 plugin · 60 total installs
How We Detect Dooodl
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dooodl/assets/migration_manager.js/wp-content/plugins/dooodl/assets/admin_style.css/wp-content/plugins/dooodl/creator/css/screen.css/wp-content/plugins/dooodl/creator/js/script.js/wp-content/plugins/dooodl/gallery/css/style.css/wp-content/plugins/dooodl/gallery/js/script.js/wp-content/plugins/dooodl/assets/migration_manager.js/wp-content/plugins/dooodl/creator/js/script.js/wp-content/plugins/dooodl/gallery/js/script.jsver=2.3.0HTML / DOM Fingerprints
dooodl-creator-wrapperdooodl-gallery-wrapperdooodl-image-container<!-- Dooodl --><!-- Dooodl Creator --><!-- Dooodl Gallery -->data-dooodl-ajax-urldata-dooodl-noncedata-dooodl-image-idwindow.dooodl_ajax_urlwindow.dooodl_noncevar DooodlAdminLabels[dooodl_creator][dooodl_gallery]