eewee pinterest Security & Risk Analysis

wordpress.org/plugins/eewee-pinterest

Use the wordpress administration to place your Pinterest widget on an area (header, footer) and / or use a shortcode to display the widget Pinterest.

10 active installs v1.3.3 PHP + WP 3.0+ Updated Sep 5, 2014
pinterestpositionshortcodewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is eewee pinterest Safe to Use in 2026?

Generally Safe

Score 85/100

eewee pinterest has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "eewee-pinterest" v1.3.3 plugin exhibits a mixed security posture. While the plugin demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no known vulnerabilities or CVEs, there are significant concerns regarding output escaping and taint analysis. The static analysis revealed that 100% of output operations are not properly escaped, which is a critical security weakness that could lead to cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified 3 flows with unsanitized paths, indicating potential pathways for malicious data to enter the application without proper cleaning. Although these taint flows are not classified as critical or high severity and no CVEs are recorded, the lack of output escaping and unsanitized paths are substantial risks that require immediate attention. The plugin's limited attack surface and absence of known past vulnerabilities are positive aspects, but the identified code-level weaknesses present a clear and present danger if exploited.

Key Concerns

  • All output operations are unescaped
  • Taint flows with unsanitized paths detected
Vulnerabilities
None known

eewee pinterest Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

eewee pinterest Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped10 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
getForm (forms\addPinterest.php:9)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

eewee pinterest Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[eeweepinterest] controllers\EeweePinterest.php:7
[eeweepinterestbtn] controllers\EeweePinterest.php:8
WordPress Hooks 7
actionadmin_initcontrollers\EeweePinterest.php:38
actionwp_footercontrollers\EeweePinterest.php:60
actionwp_headcontrollers\EeweePinterest.php:65
actionwp_footercontrollers\EeweePinterest.php:69
actionwp_enqueue_scriptsindex.php:31
actionwp_enqueue_scriptsindex.php:44
actionadmin_menuindex.php:81
Maintenance & Trust

eewee pinterest Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 5, 2014
PHP min version
Downloads4K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

eewee pinterest Developer Profile

eewee

5 plugins · 50 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect eewee pinterest

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eewee-pinterest/css/style.css/wp-content/plugins/eewee-pinterest/img/icon.png
Script Paths
http://assets.pinterest.com/js/pinit.js

HTML / DOM Fingerprints

Data Attributes
data-pin-scale-widthdata-pin-scale-heightdata-pin-board-widthdata-pin-dodata-pin-do="embedUser"data-pin-do="embedBoard"+1 more
Shortcode Output
<a data-pin-do="embedBoard" href=<a data-pin-do="buttonFollow" href=
FAQ

Frequently Asked Questions about eewee pinterest