Get your plurk Security & Risk Analysis

wordpress.org/plugins/get-your-plurk

"Get your Plurk" could get your plurks from www.plurk.com, and show it on your sidebar. You may enable cache option to save the PHP page ger …

10 active installs v1.1.3 PHP + WP 2.1+ Updated Dec 24, 2008
plurk
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Get your plurk Safe to Use in 2026?

Generally Safe

Score 85/100

Get your plurk has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The 'get-your-plurk' plugin version 1.1.3 demonstrates a strong adherence to secure coding practices in several key areas, particularly in its handling of SQL queries, which are exclusively executed using prepared statements. Furthermore, the absence of identified CVEs and a clean vulnerability history suggests a well-maintained and secure plugin to date. The limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, is a significant positive security indicator. However, the analysis reveals a critical weakness: 0% of output is properly escaped. This means that user-supplied data, if processed by the plugin and displayed on the frontend or backend, could be vulnerable to Cross-Site Scripting (XSS) attacks. The complete lack of nonce and capability checks, combined with the absence of taint analysis flows, while seemingly indicating no immediate issues found, could also mean that potential vulnerabilities in these areas were not thoroughly analyzed or are present but not detected by the specific analysis performed. The presence of file operations without further detail on their nature also warrants caution. Overall, while the plugin's foundation appears solid regarding data storage and entry points, the unescaped output presents a significant and immediate risk that needs addressing.

Key Concerns

  • Output not properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Get your plurk Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Get your plurk Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped11 total outputs
Attack Surface

Get your plurk Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedget-plurk.php:203
actionwp_headget-plurk.php:204
Maintenance & Trust

Get your plurk Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedDec 24, 2008
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Get your plurk Developer Profile

roga

5 plugins · 20 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Get your plurk

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/get-your-plurk/style.css

HTML / DOM Fingerprints

CSS Classes
gyp-get-plurksgyp-fancygyp-userlinkgyp-plurk-timegyp-plurk-detail
Data Attributes
gyp-plurk-usernamegyp-plurk-countsgyp-plurk-publish-timegyp-plurk-timediffgyp-plurk-langgyp-plurk-show-username+1 more
FAQ

Frequently Asked Questions about Get your plurk