
Foyer – Digital Signage for WordPress Security & Risk Analysis
wordpress.org/plugins/foyerA free Digital Signage plugin for WordPress. Create and show off slideshows on your networked displays.
Is Foyer – Digital Signage for WordPress Safe to Use in 2026?
Mostly Safe
Score 79/100Foyer – Digital Signage for WordPress is generally safe to use. 1 past CVE were resolved.
The "foyer" plugin, version 1.7.6, exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices in several areas, such as 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. All five identified AJAX handlers lack authentication checks, creating a substantial risk for unauthorized actions. Furthermore, the plugin has a history of known vulnerabilities, with one medium-severity Improper Authorization vulnerability remaining unpatched. This pattern suggests a recurring issue with access control within the plugin, which, when combined with the unprotected AJAX endpoints, could be exploited by attackers.
Despite the positive aspects of its code quality regarding SQL and output handling, the lack of authorization checks on critical entry points (AJAX handlers) is a major weakness. The single unpatched medium-severity vulnerability, coupled with the unprotected AJAX handlers, indicates that an attacker could potentially leverage these vulnerabilities to perform unauthorized actions or manipulate plugin behavior. While the taint analysis did not reveal critical or high-severity unsanitized flows, the existing vulnerabilities and the large unprotected attack surface demand immediate attention. The plugin's overall security posture is therefore considered vulnerable due to these critical omissions.
Key Concerns
- 5 unprotected AJAX handlers
- 1 unpatched medium severity CVE
- 3 insufficient capability checks
- 4 unsanitized paths in taint flows
Foyer – Digital Signage for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Foyer <= 1.7.5 - Content Injection via Improper Access Control
Foyer – Digital Signage for WordPress Release Timeline
Foyer – Digital Signage for WordPress Code Analysis
Output Escaping
Data Flow Analysis
Foyer – Digital Signage for WordPress Attack Surface
AJAX Handlers 5
WordPress Hooks 44
Maintenance & Trust
Foyer – Digital Signage for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Foyer – Digital Signage for WordPress Alternatives
WPScreens
wpscreens
The friendliest free digital signage system for WordPress, enabling easy screen management for shops, waiting rooms, and more.
Digital Signage
digital-signage
Create a dedicated digital signage display that automatically rotates through images from your WordPress posts.
Digitalsignagepress Lite
digitalsignagepress-lite
Digitalsignagepress lets you create, manage, and deliver messages and media to advertising displays.
ScreenCloud
screencloud
Push content from WordPress to your screens seamlessly with ScreenCloud, auto-transforming data into designs for digital signage.
Simple Presenter
simple-presenter
A simple way to create presentations that can be viewed in a web browser, meant for usage in a company by displaying it on Raspberry Pi's.
Foyer – Digital Signage for WordPress Developer Profile
1 plugin · 1K total installs
How We Detect Foyer – Digital Signage for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/foyer/admin/js/foyer-admin-min.js/wp-content/plugins/foyer/public/css/foyer-public.css/wp-content/plugins/foyer/public/js/foyer-public.js/wp-content/plugins/foyer/admin/css/foyer-admin.cssadmin/js/foyer-admin-min.jspublic/js/foyer-public.jsfoyer-admin-min.js?ver=foyer-public.css?ver=foyer-public.js?ver=foyer-admin.css?ver=HTML / DOM Fingerprints
foyer-display-outputfoyer-channel-output<!-- foyer --><!-- End foyer --><!-- BEGIN foyer -->data-foyer-display-iddata-foyer-channel-idfoyer_preview[foyer_display[foyer_channel