
GitHub User Repo Widget Security & Risk Analysis
wordpress.org/plugins/github-user-repo-widgetA simple widget that will show a list of repos for a specified GitHub user.
Is GitHub User Repo Widget Safe to Use in 2026?
Generally Safe
Score 85/100GitHub User Repo Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'github-user-repo-widget' v1.0.0 plugin exhibits a mixed security posture. On the positive side, the absence of known CVEs and a clean vulnerability history suggest a historically stable plugin. The code analysis also shows good practices in SQL query handling, with 100% using prepared statements, and no file operations or external HTTP requests are directly performed by the plugin itself. However, there are significant areas of concern. The use of the `create_function` is a critical security anti-pattern, as it can lead to arbitrary code execution if user input is not meticulously sanitized before being passed to it. Furthermore, only 30% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the lack of robust capability checks and nonce checks on potential entry points, even though the reported attack surface is currently zero. The lack of taint analysis data is also a gap, preventing a full understanding of how data flows within the plugin.
Key Concerns
- Use of dangerous function create_function
- Low percentage of properly escaped output (30%)
- No nonce checks
- No capability checks
GitHub User Repo Widget Security Vulnerabilities
GitHub User Repo Widget Code Analysis
Dangerous Functions Found
Output Escaping
GitHub User Repo Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
GitHub User Repo Widget Maintenance & Trust
Maintenance Signals
Community Trust
GitHub User Repo Widget Alternatives
Restrict Widgets
restrict-widgets
All in one widgets and sidebars management in WordPress. Allows you to hide or display widgets on specified pages and restrict access for users.
Widget Icon
widget-icon
Enhance your website with 640+ icons designed for Twitter Bootstrap. Just select an icon and display it in any widget on your WordPress site.
Display Authors Widget
display-authors-widget
Display authors by role.
Optimized Dropdown Menus
optimized-dropdown-menus
Create "spiderable" drop-down menus that every search engine will scan!
BNS Chess.com Badge
bns-chesscom-badge
Dynamically displays a Chess.com user's current rating.
GitHub User Repo Widget Developer Profile
8 plugins · 53K total installs
How We Detect GitHub User Repo Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
guthub-repo-widgetdata-id_base="ja-github"