FV Descriptions Security & Risk Analysis

wordpress.org/plugins/fv-descriptions

Simple plugin which allows you to mass edit the description fields of your choice.

60 active installs v1.9.7 PHP + WP 2.7+ Updated Dec 22, 2025
all-in-one-seodescriptionfv-simpler-seometa-descriptionseo
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 17, 2024
Safety Verdict

Is FV Descriptions Safe to Use in 2026?

Generally Safe

Score 99/100

FV Descriptions has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 17, 2024Updated 4mo ago
Risk Assessment

The "fv-descriptions" plugin v1.9.7 exhibits a generally strong security posture, with several good practices evident. The static analysis reveals a complete absence of dangerous functions, 100% of SQL queries utilizing prepared statements, and a high rate (98%) of properly escaped output. File operations and external HTTP requests are also absent, reducing potential attack vectors. The presence of four nonce checks, though not tied to specific entry points in this analysis, is a positive indicator. However, the analysis does highlight two flows with unsanitized paths, which, although not classified as critical or high severity in the taint analysis, warrant attention as they represent potential avenues for security issues. The vulnerability history indicates a single medium-severity Cross-Site Scripting (XSS) vulnerability recorded in late 2024. While this vulnerability is reported as patched, the existence of an XSS flaw, even if resolved, suggests that the plugin may have had past weaknesses in output sanitization or input handling that could be re-introduced if not rigorously maintained. Overall, the plugin demonstrates a commitment to secure coding, but the unsanitized paths and past XSS vulnerability are points of concern that require ongoing vigilance.

Key Concerns

  • Two flows with unsanitized paths
  • Past medium severity XSS vulnerability
Vulnerabilities
1 published

FV Descriptions Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-56032medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

FV Descriptions <= 1.4 - Reflected Cross-Site Scripting

Dec 17, 2024 Patched in 1.5 (386d)
Version History

FV Descriptions Release Timeline

v1.5
v1.3.31 CVE
v1.3.21 CVE
v1.3.11 CVE
v1.31 CVE
Code Analysis
Analyzed Mar 16, 2026

FV Descriptions Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
3
171 escaped
Nonce Checks
4
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

98% escaped174 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
save_my_option (fv-descriptions.php:38)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FV Descriptions Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menufv-descriptions.php:20
filterscreen_settingsfv-descriptions.php:21
actionadmin_initfv-descriptions.php:24
Maintenance & Trust

FV Descriptions Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 22, 2025
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs60
Developer Profile

FV Descriptions Developer Profile

FolioVision

19 plugins · 48K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
1098 days
View full developer profile
Detection Fingerprints

How We Detect FV Descriptions

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fv-descriptions/css/fv-descriptions.css/wp-content/plugins/fv-descriptions/js/fv-descriptions.js
Script Paths
/wp-content/plugins/fv-descriptions/js/fv-descriptions.js
Version Parameters
fv-descriptions/css/fv-descriptions.css?ver=fv-descriptions/js/fv-descriptions.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="fv-items-per-page"name="nonce"name="description_field_type"name="description_tags_type"name="fv_descriptions_field"name="action"+6 more
FAQ

Frequently Asked Questions about FV Descriptions