
Fotherplot Security & Risk Analysis
wordpress.org/plugins/fotherplotA WordPress plugin for plotting some data in a custom field against time. It uses the Google charts API to render a simple line chart.
Is Fotherplot Safe to Use in 2026?
Generally Safe
Score 85/100Fotherplot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fotherplot plugin version 0.0.9 exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known vulnerabilities in its history, several significant concerns are raised by the static analysis. The plugin has a complete lack of output escaping, meaning any data rendered to the user interface is not sanitized, creating a high risk of Cross-Site Scripting (XSS) attacks. Furthermore, the taint analysis reveals two flows with unsanitized paths, indicating potential vulnerabilities that could be exploited if they lead to sensitive operations or output. The absence of nonce and capability checks on its single entry point (a shortcode) also leaves it vulnerable to unauthorized actions or data exposure. The lack of a significant attack surface and the absence of dangerous functions are positive, but these are overshadowed by the critical issues in output handling and data sanitization.
Key Concerns
- 0% output escaping
- Taint analysis: 2 unsanitized paths
- 0 nonce checks
- 0 capability checks
Fotherplot Security Vulnerabilities
Fotherplot Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Fotherplot Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Fotherplot Maintenance & Trust
Maintenance Signals
Community Trust
Fotherplot Alternatives
Plot Over Time
plot-over-time
Uses the Google Chart Tools API for charting data in posts. Tracks up to 10 different data points, 4 chart types, & lots of customization.
Plot Over Time – Extended
plot-over-time-extended
I have used Plot Over Time for a long time when found that I needed to put multiple charts on one page and category restrictions.
Plot.wp
plotwp
Add JSON-based plots to posts and pages using the plotly.js API
Simple Graph
simple-graph
Draws a line graph of single set of date related data. Graph can be made public (i.e. sidebar widget or static page) and the data can be edited throug …
Visualizer: Tables and Charts Manager for WordPress
visualizer
A simple yet powerful WordPress chart plugin to effortlessly create and embed responsive charts & tables into your site, supporting multiple data …
Fotherplot Developer Profile
2 plugins · 20 total installs
How We Detect Fotherplot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fotherplot/fotherplot.phpHTML / DOM Fingerprints
error<h4>Chart</h4><center><img src="http://chart.apis.google.com/chart?</h4><ul>