Extended Gravatar Security & Risk Analysis
wordpress.org/plugins/extended-gravatarThis plugin brings Hovercard popups for your commenters via Gravatar
Is Extended Gravatar Safe to Use in 2026?
Generally Safe
Score 100/100Extended Gravatar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The extended-gravatar plugin version 0.6 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL queries by exclusively using prepared statements and has no recorded vulnerabilities, including CVEs. The lack of external HTTP requests and bundled libraries is also a good sign. However, the analysis reveals significant concerns in other areas. Notably, the plugin has a low percentage of properly escaped output, indicating a potential for cross-site scripting (XSS) vulnerabilities where user-supplied data might be rendered directly in the browser without proper sanitization. Furthermore, the taint analysis shows that all analyzed flows have unsanitized paths, though thankfully, these did not escalate to critical or high severity issues in this specific scan. The absence of nonce checks and capability checks across its entry points (though currently zero) points to a lack of built-in security mechanisms that could be exploited if new entry points are introduced or if existing ones are misconfigured. While the current attack surface is reported as zero, this plugin's architecture seems to lack robust security fundamentals.
Key Concerns
- Low percentage of properly escaped output
- All analyzed taint flows have unsanitized paths
- No nonce checks
- No capability checks
Extended Gravatar Security Vulnerabilities
Extended Gravatar Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Extended Gravatar Attack Surface
WordPress Hooks 5
Maintenance & Trust
Extended Gravatar Maintenance & Trust
Maintenance Signals
Community Trust
Extended Gravatar Alternatives
Gravatar Like
gravatar-like
A Wordpress.com Like plugin for self hosted wordpress sites
Gravatar Hovercards
gravatar-wordpress-plugin
This plugin enables Gravatar Hovercards in Self Hosted Wordpress Blogs. Code by Ottopress, Pluginized By Abhik.
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
User Profile Picture
metronet-profile-picture
Set a custom profile image (avatar) for a user using the standard WordPress media upload tool.
Extended Gravatar Developer Profile
6 plugins · 90 total installs
How We Detect Extended Gravatar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extended-gravatar/css/hovercard.css/wp-content/plugins/extended-gravatar/css/services.css/wp-content/plugins/extended-gravatar/js/gprofiles.jsextended-gravatar/css/hovercard.css?ver=extended-gravatar/css/services.css?ver=extended-gravatar/js/gprofiles.js?ver=HTML / DOM Fingerprints
id="gravatar-card-css"id="gravatar-card-services-css"name="extended_gravatar_url"var extended_gravatar_url =