
Family Wiki Security & Risk Analysis
wordpress.org/plugins/family-wikiKeep your family history in a wiki hosted on WordPress.
Is Family Wiki Safe to Use in 2026?
Generally Safe
Score 92/100Family Wiki has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "family-wiki" plugin v1.1.9 demonstrates a generally strong security posture based on the provided static analysis. All identified entry points (shortcodes) and code signals indicate good practices. Notably, there are no dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations and external HTTP requests further reduces the attack surface. The presence of capability checks is also a positive sign of intended access control.
However, a significant concern arises from the complete absence of nonce checks across all entry points. While the static analysis reports zero unprotected entry points and zero critical or high severity taint flows, the lack of nonce verification means that even though capability checks are present, the plugin is susceptible to Cross-Site Request Forgery (CSRF) attacks. An attacker could potentially trick a logged-in user into performing unintended actions through these shortcodes if they can be manipulated to execute arbitrary actions without a valid nonce.
The vulnerability history is entirely clean, with no recorded CVEs. This suggests either the plugin has historically been well-maintained and secured, or it has not been a target for exploitation. However, the complete lack of nonce checks represents a fundamental security oversight that could be exploited regardless of past vulnerability history. In conclusion, the plugin is technically well-coded in many aspects, but the lack of nonce protection is a notable weakness that needs immediate attention.
Key Concerns
- Missing nonce checks on all entry points
Family Wiki Security Vulnerabilities
Family Wiki Release Timeline
Family Wiki Code Analysis
Output Escaping
Family Wiki Attack Surface
Shortcodes 3
WordPress Hooks 19
Maintenance & Trust
Family Wiki Maintenance & Trust
Maintenance Signals
Community Trust
Family Wiki Alternatives
BuddyPress Docs
buddypress-docs
Adds collaborative Docs to BuddyPress.
weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot
wedocs
Build a powerful documentation hub with an AI-powered knowledge base, docs, wiki tools, and an AI chatbot to help users find answers instantly.
Knowledge Base documentation & wiki plugin – BasePress Docs
basepress
Easily create & manage documentation. Reduce support tickets & scale your customer support workload. This simple plugin works with any theme.
EazyDocs – AI Powered Knowledge Base, Wiki, Documentation & FAQ Builder
eazydocs
Build professional knowledge bases with unlimited docs, drag-and-drop editor, live search, and SEO optimization.
Yada Wiki
yada-wiki
Yada Wiki is a simple wiki for your WordPress site.
Family Wiki Developer Profile
7 plugins · 2K total installs
How We Detect Family Wiki
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/family-wiki/family-calendar.js/wp-content/plugins/family-wiki/birthday-calendar.js/wp-content/plugins/family-wiki/family-calendar.js/wp-content/plugins/family-wiki/birthday-calendar.jsHTML / DOM Fingerprints
[name_with_bio][born][died]