
Genealogical Tree – WordPress Family Tree Security & Risk Analysis
wordpress.org/plugins/genealogical-treeGenealogical Tree is a ultimate solution for creating and displaying family trees, family history, builds ancestor profiles on WordPress.
Is Genealogical Tree – WordPress Family Tree Safe to Use in 2026?
Mostly Safe
Score 78/100Genealogical Tree – WordPress Family Tree is generally safe to use. 1 past CVE were resolved. Keep it updated.
The genealogical-tree plugin v2.2.6 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL queries, exclusively using prepared statements, and a high percentage (96%) of properly escaped output, indicating a good understanding of preventing common web vulnerabilities. The presence of numerous capability checks and nonces further suggests an effort to secure the application.
However, significant concerns arise from the large attack surface exposed by unprotected AJAX handlers. With 9 out of 9 AJAX handlers lacking authentication checks, this presents a substantial risk for unauthorized actions or data manipulation. The plugin also has a known, unpatched medium severity vulnerability (CVE) related to Cross-Site Scripting, which is a serious concern that needs immediate attention.
The vulnerability history, specifically the single unpatched medium CVE, coupled with the unprotected AJAX handlers, suggests that while some security measures are in place, there are critical oversights that could be exploited. The plugin has demonstrated a past weakness in input sanitization for XSS, and the lack of authentication on AJAX endpoints creates new avenues for similar attacks.
Key Concerns
- Unprotected AJAX handlers
- Unpatched CVE (medium severity)
- Bundled Freemius v1.0 library
Genealogical Tree – WordPress Family Tree Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Genealogical Tree <= 2.2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
Genealogical Tree – WordPress Family Tree Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Genealogical Tree – WordPress Family Tree Attack Surface
AJAX Handlers 9
Shortcodes 7
WordPress Hooks 49
Maintenance & Trust
Genealogical Tree – WordPress Family Tree Maintenance & Trust
Maintenance Signals
Community Trust
Genealogical Tree – WordPress Family Tree Alternatives
GedShow
gedshow
GedShow creates a shortcode to display the contents of an uploaded gedcom file to show the family history of individuals in the file.
Genealogy
genealogy
"Being revamped" Map out your family relationships using the Genealogy plugin.
WP Family Tree
wp-family-tree
WP Family Tree is a graphical family tree generator plugin for Wordpress. Each family member have their own blog post.
Single Sign On For TNG
single-sign-on-for-tng
Single Sign On For TNG automates the login to the genealogy program TNG by Darrin Lithgoe.
FamTree
famtree
This plugin provides a block to manage and visualize family trees (Scaffolded with Create Block tool).
Genealogical Tree – WordPress Family Tree Developer Profile
2 plugins · 620 total installs
How We Detect Genealogical Tree – WordPress Family Tree
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/genealogical-tree/freemius/start.php/wp-content/plugins/genealogical-tree/admin/css/select2.min.css/wp-content/plugins/genealogical-tree/admin/css/genealogical-tree-admin.css/wp-content/plugins/genealogical-tree/admin/js/select2.full.min.js/wp-content/plugins/genealogical-tree/admin/js/genealogical-tree-admin.js/wp-content/plugins/genealogical-tree/admin/js/genealogical-tree-admin.jsgenealogical-tree/admin/css/select2.min.css?ver=genealogical-tree/admin/css/genealogical-tree-admin.css?ver=genealogical-tree/admin/js/select2.full.min.js?ver=genealogical-tree/admin/js/genealogical-tree-admin.js?ver=HTML / DOM Fingerprints
genealogical-tree-admindata-genealogical-tree-settingsgenealogical_tree_settings/wp-json/genealogical-tree