
Genealogy Security & Risk Analysis
wordpress.org/plugins/genealogy"Being revamped" Map out your family relationships using the Genealogy plugin.
Is Genealogy Safe to Use in 2026?
Generally Safe
Score 85/100Genealogy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'genealogy' plugin version 1.2.2 exhibits a generally good security posture, with no known vulnerabilities or critical taint flows. The code analysis shows responsible use of prepared statements for SQL queries and the presence of both nonce and capability checks, which are positive indicators for secure development practices. The absence of file operations and external HTTP requests further reduces the attack surface.
However, a significant concern arises from the output escaping. With only 38% of 32 outputs properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts through user-controllable data that is not adequately sanitized before being displayed to users. The limited attack surface, consisting of two shortcodes with no explicit indication of authentication or permission checks on their execution, also warrants careful examination within the plugin's actual implementation.
Given the lack of historical vulnerabilities and the positive aspects of code structure, the plugin's overall security is moderate. The primary weakness lies in the insufficient output escaping, which needs immediate attention to mitigate XSS risks. While the plugin demonstrates a commitment to core security practices like prepared statements and nonces, the output sanitization gap is a critical oversight.
Key Concerns
- Poor output escaping (XSS risk)
- Shortcodes without explicit auth/permission checks
Genealogy Security Vulnerabilities
Genealogy Code Analysis
Output Escaping
Genealogy Attack Surface
Shortcodes 2
WordPress Hooks 24
Maintenance & Trust
Genealogy Maintenance & Trust
Maintenance Signals
Community Trust
Genealogy Alternatives
Genealogical Tree – WordPress Family Tree
genealogical-tree
Genealogical Tree is a ultimate solution for creating and displaying family trees, family history, builds ancestor profiles on WordPress.
WP Family Tree
wp-family-tree
WP Family Tree is a graphical family tree generator plugin for Wordpress. Each family member have their own blog post.
GedShow
gedshow
GedShow creates a shortcode to display the contents of an uploaded gedcom file to show the family history of individuals in the file.
Single Sign On For TNG
single-sign-on-for-tng
Single Sign On For TNG automates the login to the genealogy program TNG by Darrin Lithgoe.
FamTree
famtree
This plugin provides a block to manage and visualize family trees (Scaffolded with Create Block tool).
Genealogy Developer Profile
17 plugins · 2K total installs
How We Detect Genealogy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/genealogy/css/genealogy.css/wp-content/plugins/genealogy/js/genealogy.js/wp-content/plugins/genealogy/js/admin/genealogy-admin.js/wp-content/plugins/genealogy/js/admin/genealogy-settings.js/wp-content/plugins/genealogy/js/admin/genealogy-settings-import.js/wp-content/plugins/genealogy/js/admin/genealogy-settings-export.js/wp-content/plugins/genealogy/css/genealogy.css?ver=/wp-content/plugins/genealogy/js/genealogy.js?ver=/wp-content/plugins/genealogy/js/admin/genealogy-admin.js?ver=/wp-content/plugins/genealogy/js/admin/genealogy-settings.js?ver=/wp-content/plugins/genealogy/js/admin/genealogy-settings-import.js?ver=/wp-content/plugins/genealogy/js/admin/genealogy-settings-export.js?ver=HTML / DOM Fingerprints
genealogy-treegenealogy-eventdata-genealogy-iddata-genealogy-parent-idgenealogy_settings[genealogy]