Drop it Security & Risk Analysis

wordpress.org/plugins/dropit

Easily insert free photos from unsplash.com and gifs from Giphy.com right from Gutenberg's sidebar.

80 active installs v1.3.1 PHP 5.2.4+ WP 4.8+ Updated Aug 9, 2018
dropitgutenbergmediaunsplash
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Drop it Safe to Use in 2026?

Generally Safe

Score 85/100

Drop it has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

Based on the provided static analysis, the 'dropit' v1.3.1 plugin exhibits a strong security posture with no identified vulnerabilities in its code signals or taint analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping are commendable practices. Furthermore, the plugin has no recorded CVEs, indicating a history of responsible security management. The plugin also has a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, further minimizing potential entry points for attackers. This thoroughness in security is a significant strength.

However, the complete lack of nonce checks and capability checks across all entry points is a notable concern, especially if any of the "0 entry points" were to be introduced or discovered in the future without proper security measures. While the current attack surface is zero, this absence of checks represents a potential gap that could be exploited if the plugin's functionality evolves. The lack of identified flows in taint analysis and absence of external HTTP requests are positive signs, but the overall assessment highlights excellent current security with a minor potential risk area in the absence of authentication checks on its non-existent entry points.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Drop it Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Drop it Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Drop it Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Drop it Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 9, 2018
PHP min version5.2.4
Downloads7K

Community Trust

Rating94/100
Number of ratings6
Active installs80
Developer Profile

Drop it Developer Profile

Riad Benguella

3 plugins · 140 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Drop it

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dropit/assets/css/sidebar.css/wp-content/plugins/dropit/assets/js/sidebar.js/wp-content/plugins/dropit/assets/js/vendors/lodash.min.js/wp-content/plugins/dropit/assets/js/vendors/moment.min.js/wp-content/plugins/dropit/assets/js/vendors/sweetalert2.all.min.js/wp-content/plugins/dropit/assets/js/vendors/vue.min.js/wp-content/plugins/dropit/assets/js/vendors/vue-select.js
Script Paths
/wp-content/plugins/dropit/lib/common.php/wp-content/plugins/dropit/lib/i18n-script.php/wp-content/plugins/dropit/lib/sidebar-script.php
Version Parameters
dropit/assets/css/sidebar.css?ver=dropit/assets/js/sidebar.js?ver=dropit/assets/js/vendors/lodash.min.js?ver=dropit/assets/js/vendors/moment.min.js?ver=dropit/assets/js/vendors/sweetalert2.all.min.js?ver=dropit/assets/js/vendors/vue.min.js?ver=dropit/assets/js/vendors/vue-select.js?ver=

HTML / DOM Fingerprints

CSS Classes
dropit-sidebar-wrapperdropit-unsplash-item-wrapperdropit-giphy-item-wrapper
Data Attributes
data-vue-component="DropitSidebar"data-dropit-post-id
JS Globals
window.DropitSidebarDropitSidebar
FAQ

Frequently Asked Questions about Drop it