
autometa's FOLIO Security & Risk Analysis
wordpress.org/plugins/folioIt reproduces portfolio categories and attributes in portfolios and it generates a cloud mixing categories and attributes of portfolios simply via: [p …
Is autometa's FOLIO Safe to Use in 2026?
Generally Safe
Score 85/100autometa's FOLIO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "folio" plugin v2.2 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and the consistent use of prepared statements for any potential SQL interactions are excellent indicators of secure coding practices. The plugin also demonstrates a lack of critical or high-severity taint analysis findings, suggesting that data is generally handled and processed in a safe manner.
The plugin's vulnerability history is entirely clean, with no recorded CVEs of any severity. This, combined with the static analysis findings, suggests a mature and well-maintained codebase. The lack of any identified vulnerabilities over time indicates a proactive approach to security by the developers, or at least a history of prompt patching and secure development.
However, a notable area for potential concern, though not explicitly flagged as a vulnerability in the provided data, is the absence of explicit nonce checks and capability checks for its identified entry points (shortcodes). While the static analysis reports 0 unprotected entry points, the lack of documented checks means that the actual protection mechanisms for these shortcodes are not detailed here. If these shortcodes handle user-supplied data or perform sensitive actions, the absence of explicit checks could represent a latent risk. Overall, the plugin is very secure, with its primary potential weakness lying in the implicit security of its shortcode implementations.
Key Concerns
- Missing nonce checks for shortcodes
- Missing capability checks for shortcodes
autometa's FOLIO Security Vulnerabilities
autometa's FOLIO Code Analysis
autometa's FOLIO Attack Surface
Shortcodes 3
Maintenance & Trust
autometa's FOLIO Maintenance & Trust
Maintenance Signals
Community Trust
autometa's FOLIO Alternatives
autometa's CATAG
catag
It reproduces categories and tags in posts and it generates a cloud mixing categories and tags of posts simply via: [cats] and [tags] and [catag].
Tags All In One
tags-all-in-one
Display a customizable tag cloud from selected taxonomies with various sorting and styling options.
autometa
autometa
It reproduces metadata information and it generates taxonomy clouds and comment and search forms to publications simply via shortcodes.
autometa's DATED
dated
It reproduces publication dates in pages, posts, portfolios or products simply via: [dated].
autometa's THUMB
thumb
It reproduces featured images in pages, posts, portfolios or products simply via: [thumb].
autometa's FOLIO Developer Profile
7 plugins · 90 total installs
How We Detect autometa's FOLIO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
autometaid="pfcats"id="pfatts"id="folio"<span id="pfcats" class="autometa"><span id="pfatts" class="autometa"><span id="folio" class="autometa">