
Drop it Security & Risk Analysis
wordpress.org/plugins/dropitEasily insert free photos from unsplash.com and gifs from Giphy.com right from Gutenberg's sidebar.
Is Drop it Safe to Use in 2026?
Generally Safe
Score 85/100Drop it has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis, the 'dropit' v1.3.1 plugin exhibits a strong security posture with no identified vulnerabilities in its code signals or taint analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping are commendable practices. Furthermore, the plugin has no recorded CVEs, indicating a history of responsible security management. The plugin also has a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further minimizing potential entry points for attackers. This thoroughness in security is a significant strength.
However, the complete lack of nonce checks and capability checks across all entry points is a notable concern, especially if any of the "0 entry points" were to be introduced or discovered in the future without proper security measures. While the current attack surface is zero, this absence of checks represents a potential gap that could be exploited if the plugin's functionality evolves. The lack of identified flows in taint analysis and absence of external HTTP requests are positive signs, but the overall assessment highlights excellent current security with a minor potential risk area in the absence of authentication checks on its non-existent entry points.
Key Concerns
- No nonce checks
- No capability checks
Drop it Security Vulnerabilities
Drop it Code Analysis
Drop it Attack Surface
Maintenance & Trust
Drop it Maintenance & Trust
Maintenance Signals
Community Trust
Drop it Alternatives
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
Algori Social Share Buttons
social-share-buttons-lite
Algori Social Share Buttons is a Gutenberg Block Plugin that enables you add Social Media Share Buttons to your website.
Inline Tweet Sharer – Twitter Sharing Plugin
inline-tweet-sharer
Inline Tweet Sharer is a plugin that allows you to easily and simply create links to share your content on twitter. These links share whatever the anc …
GutenDraw – Visualize Ideas with Excalidraw
gutendraw
GutenDraw: share your story with interactive diagrams and flowcharts directly in the WordPress that resonates with your audience
Image Slider Blocks
image-slider-block
An image slider block plugin for Gutenberg blocks
Drop it Developer Profile
3 plugins · 140 total installs
How We Detect Drop it
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dropit/assets/css/sidebar.css/wp-content/plugins/dropit/assets/js/sidebar.js/wp-content/plugins/dropit/assets/js/vendors/lodash.min.js/wp-content/plugins/dropit/assets/js/vendors/moment.min.js/wp-content/plugins/dropit/assets/js/vendors/sweetalert2.all.min.js/wp-content/plugins/dropit/assets/js/vendors/vue.min.js/wp-content/plugins/dropit/assets/js/vendors/vue-select.js/wp-content/plugins/dropit/lib/common.php/wp-content/plugins/dropit/lib/i18n-script.php/wp-content/plugins/dropit/lib/sidebar-script.phpdropit/assets/css/sidebar.css?ver=dropit/assets/js/sidebar.js?ver=dropit/assets/js/vendors/lodash.min.js?ver=dropit/assets/js/vendors/moment.min.js?ver=dropit/assets/js/vendors/sweetalert2.all.min.js?ver=dropit/assets/js/vendors/vue.min.js?ver=dropit/assets/js/vendors/vue-select.js?ver=HTML / DOM Fingerprints
dropit-sidebar-wrapperdropit-unsplash-item-wrapperdropit-giphy-item-wrapperdata-vue-component="DropitSidebar"data-dropit-post-idwindow.DropitSidebarDropitSidebar