GitHub & BitBucket Project Lister Security & Risk Analysis

wordpress.org/plugins/github-bitbucket-project-lister

This is a Wordpress plugin that will list your open source projects from github or bitbucket in-page or via sidebar.

10 active installs v1.2.0 PHP + WP 3.0+ Updated Unknown
bitbucketgithublistprojectprojects
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GitHub & BitBucket Project Lister Safe to Use in 2026?

Generally Safe

Score 100/100

GitHub & BitBucket Project Lister has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "github-bitbucket-project-lister" plugin, at version 1.2.0, exhibits a strong security posture in several key areas. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code shows good practice in its handling of SQL queries, with 100% using prepared statements. The lack of reported CVEs and a clean vulnerability history suggest a well-maintained and secure plugin over time. However, a critical concern arises from the complete lack of output escaping. With 26 total outputs and 0% properly escaped, this presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, allowing malicious actors to inject scripts into the user interface, potentially leading to account takeover or other malicious activities. The absence of capability checks and nonce checks also indicates a potential for privilege escalation or unauthorized actions if any entry points were to be discovered or introduced in future versions.

Key Concerns

  • 0% output escaping on 26 outputs
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

GitHub & BitBucket Project Lister Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GitHub & BitBucket Project Lister Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped26 total outputs
Attack Surface

GitHub & BitBucket Project Lister Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterthe_contentwordpress-github.php:15
actionadmin_menuwordpress-github.php:16
actionwidgets_initwordpress-github.php:17
Maintenance & Trust

GitHub & BitBucket Project Lister Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedUnknown
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

GitHub & BitBucket Project Lister Developer Profile

Kenny

3 plugins · 110 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GitHub & BitBucket Project Lister

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wpgh_projects
Shortcode Output
<ul></ul>
FAQ

Frequently Asked Questions about GitHub & BitBucket Project Lister