
GedShow Security & Risk Analysis
wordpress.org/plugins/gedshowGedShow creates a shortcode to display the contents of an uploaded gedcom file to show the family history of individuals in the file.
Is GedShow Safe to Use in 2026?
Generally Safe
Score 85/100GedShow has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'gedshow' v2.1.0 plugin exhibits a concerning security posture primarily due to a significant number of unprotected AJAX handlers and a high number of unsanitized taint flows. While the plugin shows some positive security practices, such as a decent percentage of SQL queries using prepared statements and a moderate level of output escaping, these strengths are overshadowed by critical weaknesses in its attack surface management and data sanitization. The complete lack of recorded CVEs or past vulnerabilities might suggest a history of good security, but this is severely undermined by the current static analysis findings. The high proportion of unsanitized paths identified in the taint analysis, specifically nine critical flows, indicates a direct pathway for malicious data to be processed without proper validation. This, combined with the 14 unprotected AJAX endpoints, creates a substantial risk for common web vulnerabilities like cross-site scripting (XSS) or arbitrary data manipulation. Despite a small number of file operations and no external HTTP requests, which are generally good signs, the plugin's overall security is significantly compromised by the identified unauthenticated entry points and the critical taint flows. Users should exercise extreme caution and consider this plugin a high risk until these issues are addressed.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Low output escaping percentage
- Limited capability checks
- Limited nonce checks
GedShow Security Vulnerabilities
GedShow Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
GedShow Attack Surface
AJAX Handlers 14
Shortcodes 5
WordPress Hooks 11
Maintenance & Trust
GedShow Maintenance & Trust
Maintenance Signals
Community Trust
GedShow Alternatives
Genealogical Tree – WordPress Family Tree
genealogical-tree
Genealogical Tree is a ultimate solution for creating and displaying family trees, family history, builds ancestor profiles on WordPress.
Genealogy
genealogy
"Being revamped" Map out your family relationships using the Genealogy plugin.
WP Family Tree
wp-family-tree
WP Family Tree is a graphical family tree generator plugin for Wordpress. Each family member have their own blog post.
Single Sign On For TNG
single-sign-on-for-tng
Single Sign On For TNG automates the login to the genealogy program TNG by Darrin Lithgoe.
FamTree
famtree
This plugin provides a block to manage and visualize family trees (Scaffolded with Create Block tool).
GedShow Developer Profile
1 plugin · 200 total installs
How We Detect GedShow
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gedshow/images/page.png/wp-content/plugins/gedshow/images/image.pngHTML / DOM Fingerprints
name="all_surnames"name="single_surnames"name="gedshow-btn-color"name="gedcomfn"name="childbmd"name="submit_gedshow_options"+7 moregedshow_currentgs_opts