
FlipEm Security & Risk Analysis
wordpress.org/plugins/flipemFlipEm adds CSS3 3D flipping cards to WordPress content and sidebars using shortcodes, a widget, and a live generator.
Is FlipEm Safe to Use in 2026?
Generally Safe
Score 100/100FlipEm has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "flipem" v1.1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any critical or high-severity taint flows, dangerous functions, raw SQL queries, or file operations is a significant positive. Furthermore, the high percentage of properly escaped output indicates good practices in preventing cross-site scripting vulnerabilities. The plugin also correctly implements capability checks for its entry points, which is a crucial security measure.
However, the static analysis does reveal a potential area for concern: the lack of nonce checks on its entry points. While the plugin has no unprotected entry points (meaning capability checks are present), the absence of nonces on its 3 shortcodes leaves them susceptible to Cross-Site Request Forgery (CSRF) attacks. A malicious actor could potentially trick a logged-in user into executing actions defined by these shortcodes without their explicit consent. The plugin's vulnerability history is clean, which is excellent, but this silence can also mean it hasn't been subjected to extensive scrutiny or that past versions had issues that have since been resolved. The overall impression is a well-coded plugin with a minor but exploitable oversight regarding CSRF protection on its shortcodes.
Key Concerns
- Missing nonce checks on shortcodes
FlipEm Security Vulnerabilities
FlipEm Release Timeline
FlipEm Code Analysis
Output Escaping
FlipEm Attack Surface
Shortcodes 3
WordPress Hooks 9
Maintenance & Trust
FlipEm Maintenance & Trust
Maintenance Signals
Community Trust
FlipEm Alternatives
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
Donations via PayPal
paypal-donations
Easy, simple setup to add a PayPal Donation button as a Widget or with a shortcode.
Reusable Blocks Extended
reusable-blocks-extended
Extend Gutenberg Reusable Blocks feature with a complete admin panel, widgets, shortcodes and PHP functions.
FlipEm Developer Profile
1 plugin · 0 total installs
How We Detect FlipEm
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flipem/assets/js/flipem.js/wp-content/plugins/flipem/assets/css/flipem.css/wp-content/plugins/flipem/assets/js/flipem.jsflipem/assets/css/flipem.css?ver=flipem/assets/js/flipem.js?ver=HTML / DOM Fingerprints
flipem-cardflipem-card__faceflipem-card__face--frontflipem-card__face--backflipem-card--overflipem-card--topflipem-card--rightflipem-card--bottom+3 moreFlipEm card frontFlipEm card backdata-flipem-autoflipdata-flipem-autoflipstartdata-flipem-directionflipem_init[flipem]