Enable virtual card upload – vcf,vcard Security & Risk Analysis

wordpress.org/plugins/enable-virtual-card-upload-vcardvcf

Enables upload of virtual card (vcf,vcard) files.

7K active installs v2.3.1 PHP 5.6+ WP 3.7+ Updated Mar 2, 2026
uploadvcardvcf
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Enable virtual card upload – vcf,vcard Safe to Use in 2026?

Generally Safe

Score 100/100

Enable virtual card upload – vcf,vcard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the static analysis, this plugin appears to have a strong security posture. The complete absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and any identified taint flows is highly commendable. Furthermore, the lack of any recorded vulnerabilities, critical or otherwise, in its history suggests a diligent development process focused on security. The plugin also demonstrates good practices by implementing necessary checks where entry points exist, though in this case, there are no identified entry points like AJAX handlers, REST API routes, shortcodes, or cron events. This indicates a potentially very minimal attack surface. However, the fact that there are zero capability checks and zero nonce checks is a notable observation. While this may be due to the lack of exploitable entry points currently identified, it represents a potential area for concern if any new entry points are introduced in the future without proper security implementations. Overall, the plugin presents as secure due to its current code and history, but vigilance regarding future development and the absence of fundamental security checks should be maintained.

Key Concerns

  • Zero capability checks found
  • Zero nonce checks found
Vulnerabilities
None known

Enable virtual card upload – vcf,vcard Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Enable virtual card upload – vcf,vcard Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Enable virtual card upload – vcf,vcard Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
filterupload_mimesprdb-enable-virtual-card-upload.php:40
filterwp_check_filetype_and_extprdb-enable-virtual-card-upload.php:41
Maintenance & Trust

Enable virtual card upload – vcf,vcard Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 2, 2026
PHP min version5.6
Downloads22K

Community Trust

Rating80/100
Number of ratings4
Active installs7K
Developer Profile

Enable virtual card upload – vcf,vcard Developer Profile

Amit Verma

1 plugin · 7K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Enable virtual card upload – vcf,vcard

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Enable virtual card upload – vcf,vcard