
flickree Security & Risk Analysis
wordpress.org/plugins/flickreeEasily get photos from flickr based on a photo, photoset or group ID, a gallery URL or a search text or tag.
Is flickree Safe to Use in 2026?
Generally Safe
Score 85/100flickree has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The flickree plugin, version 0.5, exhibits a mixed security posture with several concerning findings juxtaposed against some good practices. While the absence of recorded CVEs and the consistent use of prepared statements for SQL queries are positive indicators, the plugin has a significant number of unprotected entry points. Specifically, two AJAX handlers lack authentication checks, which could allow unauthenticated users to trigger potentially sensitive functionality. Furthermore, the analysis reveals the presence of dangerous functions like `unserialize` and `create_function`, which are often exploited in various attacks if not handled with extreme care. The complete lack of output escaping is a critical weakness, leaving the plugin vulnerable to Cross-Site Scripting (XSS) attacks. The absence of taint analysis results is neutral, as it indicates no specific flows were identified during the analysis, but it doesn't guarantee the absence of such vulnerabilities.
Despite the lack of historical vulnerabilities, the current code analysis highlights several areas of concern that significantly elevate the risk. The combination of unprotected AJAX endpoints and the lack of output escaping creates a readily exploitable attack surface for XSS and potentially other injection-based vulnerabilities. The use of `unserialize` and `create_function` without proper sanitization or contextual checks is also a red flag. While the plugin demonstrates good practices in SQL query handling, the identified weaknesses in input sanitization and output escaping are more immediate and severe threats. Therefore, this plugin should be treated with caution and ideally updated or patched to address these identified security flaws.
Key Concerns
- Unprotected AJAX handlers
- Dangerous functions: unserialize, create_function
- Output escaping: 0% properly escaped
- Missing nonce checks
flickree Security Vulnerabilities
flickree Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
flickree Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
flickree Maintenance & Trust
Maintenance Signals
Community Trust
flickree Alternatives
Flickr Photo Album
tantan-flickr
This Flickr plugin for WordPress will allow you to pull in your Flickr photosets and display them as albums on your WordPress site.
Flickr API
flickrapi
This plugin is an amended version of flickrRSS by "eightface". As well as allowing you to integrate Flickr photos into your site, supportin …
Flickr API
flickr-api
A comprehensive Flickr plugin that makes it easy to show off your images in style.
Lightbox with PhotoSwipe
lightbox-photoswipe
Integration of PhotoSwipe (http://photoswipe.com) for WordPress.
Album Gallery For Flickr
flickr-album-gallery
Display Flickr albums on WordPress with lightbox preview, SEO-friendly galleries, and easy shortcode integration.
flickree Developer Profile
3 plugins · 520 total installs
How We Detect flickree
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flickree/tinymce.css/wp-content/plugins/flickree/tinymce.js/wp-content/plugins/flickree/tinymce.jsHTML / DOM Fingerprints
flickree-wrapflickree_options[report]id="flickree_options[apikey]"id="flickree_options[report]"id="flickree_options[cc]"id="flickree-wrap"flickreeflickree_options