
Global Setting Security & Risk Analysis
wordpress.org/plugins/global-settingsGlobal Setting allows you to add, update and delete the global variables for your blog. Get Paid version at : http://just4u.x10.bz/global
Is Global Setting Safe to Use in 2026?
Generally Safe
Score 85/100Global Setting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "global-settings" plugin v1.1 exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs), no bundled libraries, and no external HTTP requests, which are all excellent indicators of good security hygiene. The attack surface is also minimal, with only one shortcode and no AJAX handlers or REST API routes that are exposed without authentication checks.
However, the static analysis reveals significant concerns regarding data handling. Specifically, the plugin performs SQL queries without using prepared statements, which is a critical vulnerability that could lead to SQL injection. Furthermore, all output is unescaped, presenting a high risk of cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on its entry points, combined with the lack of taint analysis data, suggests a potential for other unaddressed security flaws, especially if the shortcode handler is not robustly secured.
Given the lack of historical vulnerabilities, it's possible the plugin has not been extensively targeted or that its limited functionality has not exposed deeper issues. Nonetheless, the identified SQL and XSS risks are severe and require immediate attention. The plugin's strengths lie in its minimal attack surface and clean vulnerability history, but these are overshadowed by critical flaws in data sanitization and secure coding practices.
Key Concerns
- Raw SQL queries without prepared statements
- No output escaping for any output
- Missing nonce checks
- Missing capability checks
Global Setting Security Vulnerabilities
Global Setting Code Analysis
SQL Query Safety
Output Escaping
Global Setting Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Global Setting Maintenance & Trust
Maintenance Signals
Community Trust
Global Setting Alternatives
Custom Global Variables
custom-global-variables
Easily create custom variables that can be accessed globally in Wordpress and PHP. Retrieval of information is extremely fast, with no database calls.
Import / Export Customizer Settings
astra-import-export
Astra theme customizer offers several settings for header/footer layout, sidebar and blog designs, colors, backgrounds, typography and much more.
Simple HTML Sitemap
display-html-sitemap
Simple HTML Sitemap creates beautiful sitemap for you website with it's dedicated shortcode.
CFS Options Screens
cfs-options-screens
Create options screens that utilize Custom Field Suite
Admin Customization
admin-customization
Customize your Wordpress backend.
Global Setting Developer Profile
2 plugins · 110 total installs
How We Detect Global Setting
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/global-settings/download.pngHTML / DOM Fingerprints
global