
{eac}Doojigger Readme Extension for WordPress Security & Risk Analysis
wordpress.org/plugins/eacreadme{eac}Readme loads and translates a WordPress markdown 'readme' file providing shortcodes and embedding URLs to access header lines and section blocks.
Is {eac}Doojigger Readme Extension for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100{eac}Doojigger Readme Extension for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "eacreadme" v1.5.1 plugin presents a mixed security picture. On the positive side, the plugin exhibits excellent practices regarding SQL queries, exclusively using prepared statements, and all identified output is properly escaped, minimizing risks of cross-site scripting (XSS). Furthermore, there is no recorded vulnerability history, suggesting a generally secure codebase over time. The absence of external HTTP requests and bundled libraries also reduces the attack surface related to third-party vulnerabilities.
However, the static analysis reveals significant concerns. The presence of the `unserialize` function is a critical red flag. Without proper sanitization or validation of the data being unserialized, this function can lead to Remote Code Execution (RCE) vulnerabilities. While the taint analysis did not flag critical or high severity flows, the fact that there are "flows with unsanitized paths" warrants caution, especially when combined with `unserialize`. Additionally, the complete lack of nonce checks and capability checks, particularly if any functionality were to be exposed through future updates or undocumented means, represents a significant oversight in securing actions within the plugin.
In conclusion, while "eacreadme" v1.5.1 has strengths in its handling of SQL and output, the presence of `unserialize` and the absence of robust authentication and authorization mechanisms (nonces, capability checks) are significant weaknesses. The lack of historical vulnerabilities is a positive indicator but does not negate the inherent risks identified in the current code analysis.
Key Concerns
- Use of unserialize function without checks
- Taint flows with unsanitized paths found
- No nonce checks implemented
- No capability checks implemented
{eac}Doojigger Readme Extension for WordPress Security Vulnerabilities
{eac}Doojigger Readme Extension for WordPress Release Timeline
{eac}Doojigger Readme Extension for WordPress Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
{eac}Doojigger Readme Extension for WordPress Attack Surface
WordPress Hooks 7
Maintenance & Trust
{eac}Doojigger Readme Extension for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
{eac}Doojigger Readme Extension for WordPress Alternatives
Markdown Shortcode
markdown-shortcode
Damn simple markdown for wordpress via shortcode, uses parsedown (parsedown.org) and highlight.js (highlightjs.org).
Github README
github-readme
Easily embed GitHub READMEs in pages/posts.
Readme Generator
readme-generator
A simple plugin to convert a HTML post or page content into a plugin readme.txt file.
MetaParsedown
metaparsedown
Import markdown and markdown-extra documents to Wordpress posts and pages, output as HTML, parse and save YAML front matter to post_meta, tags, and (o …
Import Markdown – Versatile Markdown Importer
import-markdown
Import Markdown lets you easily generates posts based on Markdown files.
{eac}Doojigger Readme Extension for WordPress Developer Profile
11 plugins · 60 total installs
How We Detect {eac}Doojigger Readme Extension for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eacreadme/vendor/prism/prism.css/wp-content/plugins/eacreadme/vendor/prism/prism.js/wp-content/plugins/eacreadme/vendor/prism/prism.jseacreadme/vendor/prism/prism.js?ver=eacreadme/vendor/prism/prism.css?ver=HTML / DOM Fingerprints
language-phplanguage-javascriptlanguage-csslanguage-htmllanguage-cliketokencommentprolog+33 more<!-- {eac}Readme loads and translates a WordPress readme.txt file providing shortcodes to access header lines, section blocks, or the entire document. -->data-languagePrism[eacReadme][eacReadme plugin='eacreadme/readme.txt']