
Extended Profile Security & Risk Analysis
wordpress.org/plugins/extended-profileExtend the WordPress profile to include additional attributes, and output as hCard.
Is Extended Profile Safe to Use in 2026?
Generally Safe
Score 100/100Extended Profile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "extended-profile" plugin vtrunk exhibits a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, utilizing prepared statements exclusively. The static analysis also indicates a limited attack surface with only one shortcode as an entry point, and no discovered CVEs in its history. However, several significant concerns emerge from the code analysis. The presence of the "exec" dangerous function is a major red flag, as it can be leveraged for arbitrary code execution if not handled with extreme care and proper sanitization. Furthermore, a complete lack of output escaping is highly problematic, leaving the plugin vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks on its entry points also indicates a potential for unauthorized actions or privilege escalation.
Key Concerns
- Dangerous function 'exec' found
- 0% of output properly escaped
- No nonce checks
- No capability checks
Extended Profile Security Vulnerabilities
Extended Profile Code Analysis
Dangerous Functions Found
Output Escaping
Extended Profile Attack Surface
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
Extended Profile Maintenance & Trust
Maintenance Signals
Community Trust
Extended Profile Alternatives
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
One User Avatar | User Profile Picture
one-user-avatar
Use any image from your WordPress Media Library as a custom user avatar or user profile picture. Add your own Default Avatar.
Simple Local Avatars
simple-local-avatars
Adds an avatar upload field to user profiles. Generates requested sizes on demand just like Gravatar!
Simple Social Icons
simple-social-icons
This plugin provides two ways to display social icons: a traditional widget (available on all WordPress versions) and block variations for the core So …
Extended Profile Developer Profile
5 plugins · 11K total installs
How We Detect Extended Profile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extended-profile/profile.css/wp-content/plugins/extended-profile/preview.js/wp-content/plugins/extended-profile/preview.jsextended-profile/profile.css?ver=extended-profile/preview.js?ver=HTML / DOM Fingerprints
hkit[profile]