
Gleam: Run Competitions on Your WordPress Blog Security & Risk Analysis
wordpress.org/plugins/gleamAn amazing solution to run competitions on your blog using combinations of social actions.
Is Gleam: Run Competitions on Your WordPress Blog Safe to Use in 2026?
Generally Safe
Score 85/100Gleam: Run Competitions on Your WordPress Blog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gleam" v1.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, SQL injection vulnerabilities, or file operations, with all SQL queries utilizing prepared statements and all outputs being properly escaped. The plugin also shows no external HTTP requests and no evident vulnerabilities in its vulnerability history, suggesting a well-maintained and secure codebase. The absence of critical or high-severity taint flows further reinforces this positive assessment.
However, a potential area of concern is the lack of nonce and capability checks. While the attack surface is currently small with only one shortcode, the absence of these fundamental security checks means that if this shortcode were to perform any sensitive actions or accept user-provided data that is not strictly validated and escaped at the point of use, it could potentially be exploited. The overall conclusion is that "gleam" v1.0 appears to be a secure plugin with excellent coding practices, but the oversight in implementing nonce and capability checks represents a minor weakness that could be addressed.
Key Concerns
- Missing nonce checks
- Missing capability checks
Gleam: Run Competitions on Your WordPress Blog Security Vulnerabilities
Gleam: Run Competitions on Your WordPress Blog Code Analysis
Gleam: Run Competitions on Your WordPress Blog Attack Surface
Shortcodes 1
Maintenance & Trust
Gleam: Run Competitions on Your WordPress Blog Maintenance & Trust
Maintenance Signals
Community Trust
Gleam: Run Competitions on Your WordPress Blog Alternatives
Curator.io
curatorio
Aggregate and embed your social media posts on your site (Facebook, Twitter, Instagram, Pinterest and many more) as a beautiful social media feed.
WP SlideYourNet
wp-slideyournet
Insert posts from social media in pWordPress with this SlideYourNet connector.
Open Graph and Twitter Card Tags
wonderm00ns-simple-facebook-open-graph-tags
Improve social media sharing by inserting Facebook Open Graph, Twitter Card, and SEO Meta Tags on your WordPress website pages, posts, WooCommerce pro …
Social Media Widget
social-media-widget
Adds links to all of your social media and sharing site profiles. Tons of icons come in 3 sizes, 4 icon styles, and 4 animations.
Tagembed: Embed Twitter Feed, Google Reviews, YouTube Videos, TikTok, RSS Feed & More Social Media Feeds
tagembed-widget
Collect & Embed Instagram Feed, Embed Facebook Feed, Embed YouTube Videos, Embed Twitter Feed, Google Reviews & 15+ Social Media Feed on website.
Gleam: Run Competitions on Your WordPress Blog Developer Profile
1 plugin · 200 total installs
How We Detect Gleam: Run Competitions on Your WordPress Blog
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gleam/e.js//js.gleam.io/e.jsHTML / DOM Fingerprints
e-gleam<a class="e-gleam"