
GitHub Mini Profile Widget Security & Risk Analysis
wordpress.org/plugins/f13-github-mini-profile-widgetAdd a snapshot of your GitHub profile to your website with with this widget.
Is GitHub Mini Profile Widget Safe to Use in 2026?
Generally Safe
Score 100/100GitHub Mini Profile Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'f13-github-mini-profile-widget' plugin version 1.1 exhibits a mixed security posture. On the positive side, it has no recorded CVEs, a completely clean taint analysis, and all its SQL queries are properly prepared, indicating good practices in these areas. It also doesn't appear to expose a large attack surface through AJAX, REST API, or shortcodes without authentication. However, there are significant concerns regarding code quality and security checks. The presence of the deprecated and insecure `create_function` is a major red flag, as this function can easily lead to code injection vulnerabilities if not handled with extreme care. Furthermore, only 25% of its output is properly escaped, leaving it vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks, especially given it makes external HTTP requests, further exacerbates these risks. While its vulnerability history is clean, this could be due to its relatively limited attack surface or a lack of comprehensive security auditing rather than inherent security. The potential for code injection via `create_function` and XSS due to insufficient output escaping are the most pressing concerns.
Key Concerns
- Use of deprecated and insecure create_function
- Only 25% of outputs are properly escaped
- No nonce checks on entry points
- No capability checks on entry points
GitHub Mini Profile Widget Security Vulnerabilities
GitHub Mini Profile Widget Code Analysis
Dangerous Functions Found
Output Escaping
GitHub Mini Profile Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
GitHub Mini Profile Widget Maintenance & Trust
Maintenance Signals
Community Trust
GitHub Mini Profile Widget Alternatives
GitHub Repository Shortcode
f13-github-repo-shortcode
Add a snapshot of your GitHub repository to any page or post on your WordPress blog.
Social Accounts
social-accounts
Add a new section under Settings for your social accounts. The order and the images can be customized with ease.
Widget Github Profile
widget-github-profile
Shows your github profile in detail.
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
GitHub Mini Profile Widget Developer Profile
8 plugins · 90 total installs
How We Detect GitHub Mini Profile Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/f13-github-mini-profile-widget/github-profile-widget.cssHTML / DOM Fingerprints
gmpw-containergmpw-head-linkgmpw-headgmpw-headdergmpw-profile-picturegmpw-namesgmpw-namegmpw-user+3 moreid="f13-gmpw-style"