Dribbble Portfolio Security & Risk Analysis

wordpress.org/plugins/dribbble-portfolio

Display dribbble.com shots to your website

10 active installs v1.0 PHP + WP 3.8+ Updated Jun 9, 2015
dribbble-portfolio-wordpressdribbble-shotsdribbble-shots-display-websitedribbble-shots-wordpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dribbble Portfolio Safe to Use in 2026?

Generally Safe

Score 85/100

Dribbble Portfolio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The dribbble-portfolio plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL query protection, utilizing prepared statements exclusively, and it has no recorded vulnerabilities or CVEs. Furthermore, the static analysis found no dangerous functions, no external HTTP requests, and no taint flows that indicate immediate exploitability. However, significant concerns arise from the lack of proper output escaping, with 0% of outputs being properly escaped. This is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever displayed on the frontend. Additionally, the absence of nonce checks and capability checks on its single shortcode entry point is a substantial risk, potentially allowing unauthorized users to trigger its functionality. While the plugin has a clean history, the current code analysis reveals critical areas for improvement that must be addressed to ensure a secure user experience.

Key Concerns

  • 0% output escaping
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Dribbble Portfolio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Dribbble Portfolio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped12 total outputs
Attack Surface

Dribbble Portfolio Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[deribble_shots] index.php:23
Maintenance & Trust

Dribbble Portfolio Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 9, 2015
PHP min version
Downloads2K

Community Trust

Rating50/100
Number of ratings2
Active installs10
Developer Profile

Dribbble Portfolio Developer Profile

PluginsPoint

20 plugins · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Dribbble Portfolio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dribbble-portfolio/css/style.css/wp-content/plugins/dribbble-portfolio/js/kento-deribble-ajax.js
Script Paths
/wp-content/plugins/dribbble-portfolio/js/kento-deribble-ajax.js
Version Parameters
dribbble-portfolio/css/style.css?ver=dribbble-portfolio/js/kento-deribble-ajax.js?ver=

HTML / DOM Fingerprints

CSS Classes
deribble-playerderibble-player-thumbderibble-player-namederibble-player-locationds-itemsds-items-thumbsds-items-nameds-items-info+4 more
Data Attributes
link
Shortcode Output
<div id='deribble-shots'><div class='deribble-player'><div class='deribble-player-thumb'><img src='
FAQ

Frequently Asked Questions about Dribbble Portfolio