Encyclopedia / Glossary / Wiki Security & Risk Analysis

wordpress.org/plugins/encyclopedia-lexicon-glossary-wiki-dictionary

Supercharged tool to build your own awesome Encyclopedia / Lexicon / Glossary / Wiki / Dictionary / Knowledge base / Directory / Vocabulary in no time

1K active installs v1.7.61 PHP 7.4+ WP 5.5+ Updated Oct 7, 2024
dictionaryencyclopediaglossarylexiconwiki
91
A · Safe
CVEs total1
Unpatched0
Last CVEOct 15, 2024
Safety Verdict

Is Encyclopedia / Glossary / Wiki Safe to Use in 2026?

Generally Safe

Score 91/100

Encyclopedia / Glossary / Wiki has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 15, 2024Updated 1yr ago
Risk Assessment

The "encyclopedia-lexicon-glossary-wiki-dictionary" plugin v1.7.61 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no file operations, no external HTTP requests, and all SQL queries utilize prepared statements, which are strong indicators of secure coding practices. The total entry points are zero, and the single nonce check, while present, is not tied to any explicit AJAX or REST API handlers in the provided data. However, a significant concern is the very low percentage (13%) of properly escaped output. This indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly into the HTML without proper sanitization. The vulnerability history, with a past medium-severity XSS vulnerability, further corroborates this concern. The absence of capability checks on any potential entry points (though there are none listed) could also be a concern if new entry points were introduced without proper authorization checks. While the lack of readily apparent attack vectors in the static analysis is encouraging, the pervasive issue with output escaping and the historical presence of XSS suggest that this plugin has potential weaknesses that require careful monitoring and remediation.

Key Concerns

  • Low output escaping percentage (13%)
  • Past medium-severity XSS vulnerability
Vulnerabilities
1

Encyclopedia / Glossary / Wiki Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-49320medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Encyclopedia / Glossary / Wiki <= 1.7.60 - Reflected Cross-Site Scripting

Oct 15, 2024 Patched in 1.7.61 (4d)
Code Analysis
Analyzed Mar 16, 2026

Encyclopedia / Glossary / Wiki Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
141
22 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared7 total queries

Output Escaping

13% escaped163 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<searchform-encyclopedia> (templates\searchform-encyclopedia.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Encyclopedia / Glossary / Wiki Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 55
actionplugins_loadedincludes\advanced-custom-fields.php:9
filteracf/format_value/type=wysiwygincludes\advanced-custom-fields.php:18
filteracf/format_value/type=textareaincludes\advanced-custom-fields.php:19
filteracf/format_value/type=textincludes\advanced-custom-fields.php:20
filterbp_get_activity_content_bodyincludes\buddypress.php:9
filterbp_get_activity_content_bodyincludes\buddypress.php:10
filterthe_contentincludes\content-filter.php:9
filterthe_contentincludes\content-filter.php:10
actionplugins_loadedincludes\content-filter.php:12
filterwidget_textincludes\content-filter.php:38
actionplugins_loadedincludes\core.php:21
actionloop_startincludes\core.php:22
filterrender_blockincludes\core.php:23
actionencyclopedia_print_prefix_filterincludes\core.php:24
filterwp_robotsincludes\core.php:25
filterget_the_archive_titleincludes\core.php:26
actionadmin_menuincludes\mocking-bird.php:12
actionregistered_post_typeincludes\mocking-bird.php:13
actionall_admin_noticesincludes\mocking-bird.php:14
actionenqueue_block_editor_assetsincludes\mocking-bird.php:15
actionadmin_menuincludes\options.php:22
filterencyclopedia_translateincludes\polylang.php:11
filterencyclopedia_available_prefix_filtersincludes\polylang.php:12
actioninitincludes\post-type.php:14
filterpost_updated_messagesincludes\post-type.php:16
filterpost_type_linkincludes\post-type.php:17
filtergutenberg_can_edit_post_typeincludes\post-type.php:18
filteruse_block_editor_for_post_typeincludes\post-type.php:19
filterdisable_categories_dropdownincludes\posts-list-table.php:9
actionrestrict_manage_postsincludes\posts-list-table.php:10
actionwp_enqueue_scriptsincludes\styles.php:9
actionwp_enqueue_scriptsincludes\styles.php:10
actioninitincludes\taxonomies.php:11
actioninitincludes\taxonomies.php:12
filternav_menu_meta_box_objectincludes\taxonomies.php:13
actioninitincludes\taxonomies.php:14
filterget_the_termsincludes\taxonomy-fallbacks.php:9
filterthe_categoryincludes\taxonomy-fallbacks.php:10
filtersearch_templateincludes\template.php:9
actioninitincludes\tooltips.php:9
actionwp_enqueue_scriptsincludes\tooltips.php:10
filterquery_varsincludes\wp-query-extensions.php:11
actionpre_get_postsincludes\wp-query-extensions.php:12
filterposts_whereincludes\wp-query-extensions.php:13
filterposts_fieldsincludes\wp-query-extensions.php:14
filterposts_orderbyincludes\wp-query-extensions.php:15
actionadmin_initincludes\wpml.php:14
filterregister_post_type_argsincludes\wpml.php:15
filterencyclopedia_translateincludes\wpml.php:16
filterencyclopedia_available_prefix_filtersincludes\wpml.php:17
actionwidgets_initwidgets\items.php:23
actionwidgets_initwidgets\related-items.php:24
actionwidgets_initwidgets\search.php:23
actionwidgets_initwidgets\taxonomies.php:23
actionwidgets_initwidgets\taxonomy-cloud.php:23
Maintenance & Trust

Encyclopedia / Glossary / Wiki Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 7, 2024
PHP min version7.4
Downloads215K

Community Trust

Rating68/100
Number of ratings161
Active installs1K
Developer Profile

Encyclopedia / Glossary / Wiki Developer Profile

Dennis

2 plugins · 1K total installs

92
trust score
Avg Security Score
88/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect Encyclopedia / Glossary / Wiki

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/encyclopedia-lexicon-glossary-wiki-dictionary/assets/css/encyclopedia.css/wp-content/plugins/encyclopedia-lexicon-glossary-wiki-dictionary/assets/css/tooltips.css/wp-content/plugins/encyclopedia-lexicon-glossary-wiki-dictionary/assets/js/tooltipster.bundle.min.js/wp-content/plugins/encyclopedia-lexicon-glossary-wiki-dictionary/assets/js/tooltips.js
Script Paths
/wp-content/plugins/encyclopedia-lexicon-glossary-wiki-dictionary/assets/js/tooltipster.bundle.min.js/wp-content/plugins/encyclopedia-lexicon-glossary-wiki-dictionary/assets/js/tooltips.js
Version Parameters
encyclopedia-lexicon-glossary-wiki-dictionary/assets/js/tooltipster.bundle.min.js?ver=encyclopedia-lexicon-glossary-wiki-dictionary/assets/js/tooltips.js?ver=

HTML / DOM Fingerprints

CSS Classes
encyclopedia-tooltip
Data Attributes
data-encyclopedia-tooltip
JS Globals
Encyclopedia_Tooltips
FAQ

Frequently Asked Questions about Encyclopedia / Glossary / Wiki