
flowpaper Security & Risk Analysis
wordpress.org/plugins/flowpaper-lite-pdf-flipbookFlipbook PDF viewer - all you need is a PDF : [flipbook pdf="https://flowpaper.com/example.pdf"]
Is flowpaper Safe to Use in 2026?
Generally Safe
Score 91/100flowpaper has a strong security track record. Known vulnerabilities have been patched promptly.
The flowpaper-lite-pdf-flipbook plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The absence of external HTTP requests and bundled libraries is also a positive sign. However, the presence of two taint flows with unsanitized paths, categorized as high severity, is a significant concern, indicating potential for vulnerabilities that could be exploited if not properly handled.
The vulnerability history reveals a pattern of medium-severity vulnerabilities, specifically Cross-site Scripting (XSS). While there are currently no unpatched CVEs, the recurring nature of XSS suggests that input sanitization might be an area that requires more robust implementation. The lack of nonce checks and capability checks, combined with the presence of a shortcode which can serve as an entry point, raises questions about the overall authorization and integrity mechanisms within the plugin.
In conclusion, while the plugin has strengths in its SQL handling and output escaping, the identified high-severity taint flows and historical XSS vulnerabilities warrant attention. The absence of explicit authorization checks on its single entry point (the shortcode) coupled with the taint analysis suggests a latent risk of input manipulation. Addressing the unsanitized paths and ensuring comprehensive input validation are crucial steps to improve its security.
Key Concerns
- High severity taint flows found
- No nonce checks on entry points
- No capability checks on entry points
- Medium severity vulnerability history (XSS)
flowpaper Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
flowpaper <= 2.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
flowpaper <= 1.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
flowpaper Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
flowpaper Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
flowpaper Maintenance & Trust
Maintenance Signals
Community Trust
flowpaper Alternatives
Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer
3d-flipbook-dflip-lite
Dear Flipbook creates PDF Flipbook, 3D Flipbook, PDF viewer, PDF embed for WordPress sites. Create impressive and realistic 3D flipbooks with PDFs.
3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery
interactive-3d-flipbook-powered-physics-engine
3D FlipBook is PDF Viewer, allowing to browse images, PDFs or HTMLs as flipbook. Flipbook attracts user attention and makes more impression on him.
Real 3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder
real3d-flipbook-lite
Embed PDF files easily anywhere on your website. Display your PDFs and images as stunning, interactive 3D flipbooks directly within WordPress.
iPages – FlipBook Image & PDF Viewer
ipages-flipbook
Create interactive HTML5 flipbooks from PDFs or images instantly - turn them into online magazines, catalogs, or brochures with ease.
PDF Flipbook Heyzine
pdf-flipbook-heyzine
Make a stunning PDF flipbook. Simply select or upload the PDF for a PDF viewer that is not boring like the rest. Stand out and engage your readers.
flowpaper Developer Profile
1 plugin · 10K total installs
How We Detect flowpaper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/flowpaper-lite-pdf-flipbook/flowpaper-lite-pdf-flipbook.js/wp-content/plugins/flowpaper-lite-pdf-flipbook/style.css/wp-content/plugins/flowpaper-lite-pdf-flipbook/flowpaper-lite-pdf-flipbook.min.js/wp-content/plugins/flowpaper-lite-pdf-flipbook/flowpaper-lite-pdf-flipbook.js/wp-content/plugins/flowpaper-lite-pdf-flipbook/flowpaper-lite-pdf-flipbook.min.jsflowpaper-lite-pdf-flipbook/style.css?ver=flowpaper-lite-pdf-flipbook/flowpaper-lite-pdf-flipbook.js?ver=flowpaper-lite-pdf-flipbook/flowpaper-lite-pdf-flipbook.min.js?ver=HTML / DOM Fingerprints
[flipbook pdf=