
Freshbooks Widget Security & Risk Analysis
wordpress.org/plugins/freshbooks-wordpress-widgetThis plugin creates a simple sidebar widget that outputs the total hours billed for a FreshBooks account.
Is Freshbooks Widget Safe to Use in 2026?
Generally Safe
Score 85/100Freshbooks Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Freshbooks WordPress Widget plugin version 2.0.1 demonstrates a generally sound security posture with no recorded vulnerabilities or CVEs. The static analysis reveals a clean slate in terms of SQL queries, which are all prepared, and no file operations or external HTTP requests beyond one identified. The absence of reported vulnerabilities and the lack of known CVEs are significant strengths. However, several concerning code signals warrant attention. The presence of the `create_function` is a critical security risk as it is deprecated and can lead to code injection vulnerabilities if user-supplied input is not meticulously sanitized before being passed to it. Furthermore, the low percentage of properly escaped output (20%) indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website's pages. The lack of nonce checks and capability checks on any identified entry points, although currently having zero entry points, leaves potential future entry points highly exposed.
Key Concerns
- Use of deprecated and dangerous function create_function
- Low percentage of properly escaped output (XSS risk)
- No nonce checks on entry points
- No capability checks on entry points
Freshbooks Widget Security Vulnerabilities
Freshbooks Widget Code Analysis
Dangerous Functions Found
Output Escaping
Freshbooks Widget Attack Surface
WordPress Hooks 5
Maintenance & Trust
Freshbooks Widget Maintenance & Trust
Maintenance Signals
Community Trust
Freshbooks Widget Alternatives
Project Manager – AI Powered Project Management, Task Management, Kanban Board & Time Tracker
wedevs-project-manager
Ease Project Management and Task Management using a powerful project manager with Kanban board, Gantt chart, milestone tracking & project reporting.
FluentBoards – Project Management, Task Management, Goal Tracking, Kanban Board, and, Team Collaboration
fluent-boards
The Simplest Project & Task Management Plugin Specifically Crafted for Agencies, Freelancers & Founders.
Atarim – Visual Feedback, Review & AI Collaboration
atarim-visual-collaboration
Make collecting feedback on WordPress sites MUCH faster and easier, with the visual collaboration tool used on over 120,000 websites worldwide.
Propovoice: All-in-One Client Management System
propovoice
All-in-one client management system for freelancers & agencies on WordPress. Manage leads, deals, invoices & projects. Get paid faster!
Taskbuilder – Project Management & Task Management Tool With Kanban Board
taskbuilder
Taskbuilder is a project management and task management plugin for WordPress with Kanban-style boards to organize and track work.
Freshbooks Widget Developer Profile
2 plugins · 30 total installs
How We Detect Freshbooks Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/freshbooks-wordpress-widget/js/freshbooks-widget.js/wp-content/plugins/freshbooks-wordpress-widget/css/freshbooks-widget.css/wp-content/plugins/freshbooks-wordpress-widget/js/freshbooks-widget.jsfreshbooks-wordpress-widget/js/freshbooks-widget.js?ver=freshbooks-wordpress-widget/css/freshbooks-widget.css?ver=