
Draugiem.lv biznesa lapu sekotāju spraudnis Security & Risk Analysis
wordpress.org/plugins/draugiemlvlapas-fan-pageDraugiem.lv biznesa lapu un pasākumu fanu WordPress spraudnis draugiem.lv lietotājiem
Is Draugiem.lv biznesa lapu sekotāju spraudnis Safe to Use in 2026?
Generally Safe
Score 85/100Draugiem.lv biznesa lapu sekotāju spraudnis has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'draugiemlvlapas-fan-page' plugin version 3.5.4 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong positive indicator. Furthermore, the plugin boasts a small attack surface with only two shortcodes, and crucially, no identified entry points are unprotected.
However, the analysis does reveal a significant concern regarding output escaping. With 91 total outputs and only 9% properly escaped, there's a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. This is a critical weakness that could be exploited by attackers to inject malicious scripts into users' browsers. The complete lack of nonce and capability checks, while not directly exposed in the entry points, could become a vector for privilege escalation or unauthorized actions if vulnerabilities are found elsewhere or if the shortcodes are used in contexts where these checks are bypassed.
The plugin's vulnerability history is clean, with no recorded CVEs, which is commendable. This, combined with the absence of taint flows and dangerous functions, suggests the developers may be following good coding practices. Nevertheless, the poor output escaping remains a glaring issue that needs immediate attention. The plugin's strengths lie in its limited attack surface and absence of known critical vulnerabilities, but its weakness in output sanitization presents a tangible risk.
Key Concerns
- Poor output escaping
- No nonce checks
- No capability checks
Draugiem.lv biznesa lapu sekotāju spraudnis Security Vulnerabilities
Draugiem.lv biznesa lapu sekotāju spraudnis Release Timeline
Draugiem.lv biznesa lapu sekotāju spraudnis Code Analysis
Output Escaping
Draugiem.lv biznesa lapu sekotāju spraudnis Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
Draugiem.lv biznesa lapu sekotāju spraudnis Maintenance & Trust
Maintenance Signals
Community Trust
Draugiem.lv biznesa lapu sekotāju spraudnis Alternatives
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Image Widget
image-widget
A simple image widget that uses the native WordPress media manager to add image widgets to your site.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
WooSidebars
woosidebars
WooSidebars adds functionality to display different widgets in a sidebar, according to a context (for example, a specific page or a category).
Draugiem.lv biznesa lapu sekotāju spraudnis Developer Profile
2 plugins · 710 total installs
How We Detect Draugiem.lv biznesa lapu sekotāju spraudnis
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/draugiemlvlapas-fan-page/css/draugiem-lapas-sekotaji.csshttps://mediabox.lv/wordpress-spraudni/?utm_source=draugiemlvlapas-fan-page-3.5.4//www.draugiem.lv/api/api.jsdraugiemlvlapas-fan-page/css/draugiem-lapas-sekotaji.css?ver=HTML / DOM Fingerprints
Draugiem.lv biznesa lapu sekotāju spraudnis via https://Umbrovskis.com | https://MediaBox.lv | https://SimpleMediaCode.com / Draugiem.lv biznesa lapu sekotāju spraudnis via https://Umbrovskis.com | https://MediaBox.lv | https://SimpleMediaCode.com / beigas id="fansblockDApi.BizFans<style>#fansblockvar fans2 = new DApi.BizFans({