
furikake Security & Risk Analysis
wordpress.org/plugins/furikakeThis plug-in provides Furigana (A.K.A. "Yomigana". Japanese phonetic of Chinese characters) to the text of web pages.
Is furikake Safe to Use in 2026?
Generally Safe
Score 100/100furikake has a strong security track record. Known vulnerabilities have been patched promptly.
The furikake plugin version 0.2.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no dangerous functions, utilizing prepared statements for all SQL queries, and performing nonce and capability checks on its single entry point (a shortcode). Additionally, there are no external HTTP requests or bundled libraries, which reduces the potential for cross-dependencies and supply chain attacks. The absence of any critical or high-severity taint flows is also a strong indicator of sound coding in that area.
However, significant concerns arise from the output escaping. A mere 23% of output is properly escaped, leaving a substantial portion vulnerable to Cross-Site Scripting (XSS) attacks. While the static analysis shows no immediate critical vulnerabilities, this low escaping rate represents a considerable risk for users interacting with the plugin's output. The vulnerability history, though dated, shows a past medium-severity 'Open Redirect' vulnerability. While currently unpatched issues are zero, this historical pattern suggests that the plugin's developers may not have a consistent track record of addressing security vulnerabilities promptly or thoroughly, especially regarding input validation and output sanitization.
In conclusion, while furikake v0.2.0 has strengths in its limited attack surface and database interaction security, the critical weakness in output escaping presents a tangible XSS risk. The past medium-severity vulnerability, even though resolved, warrants caution regarding the overall security development lifecycle of the plugin. Future versions should prioritize robust output sanitization to mitigate these risks.
Key Concerns
- Low percentage of properly escaped output
- Past medium severity vulnerability history
furikake Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
furikake <= 0.1.0 - Open Redirect
furikake Code Analysis
Output Escaping
furikake Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
furikake Maintenance & Trust
Maintenance Signals
Community Trust
furikake Alternatives
BanglKB
banglkb
Bangla Typing Scripts for wordpress. This Java Script based add-ons will let your visitors type in Bangla without using any 3rd party tool or keyboard …
Bleep Filter
bleep-filter
An advanced word and content filter perfect for passively eliminating profanity and spoilers.
Indian Keyboard
indian-keyboard
Let you type in your native language using phonetic english.
OpenSearchServer Search
opensearchserver-search
The OpenSearchServer Search Plugin enables OpenSearchServer full-text search in WordPress-based websites.
Bphonetic WordCount
bphonetic-wordcount
Short Description: A lightweight plugin for Classic Editor that adds Bangla & English typing support, word count, and reading time estimation.
furikake Developer Profile
5 plugins · 210 total installs
How We Detect furikake
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
furikake_on[furikake]