Global threat activity level Widget Security & Risk Analysis

wordpress.org/plugins/global-threat-activity-level-widget

Displays global virus and spyware activity level and latest spyware threats with guidelines how to remove them.

10 active installs v1.1.6 PHP 7.3+ WP 5.8+ Updated Feb 23, 2026
activitycyber-securitymalwarethreatvirus
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Global threat activity level Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Global threat activity level Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "global-threat-activity-level-widget" v1.1.6 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of identified entry points, dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly commendable. Furthermore, the high percentage of properly escaped output suggests a good understanding of secure coding practices to prevent cross-site scripting vulnerabilities. The lack of any recorded vulnerabilities in its history is also a positive indicator of its development quality and ongoing maintenance.

However, there are a few areas that warrant attention. The complete absence of nonce checks and capability checks across all code signals is a significant concern. While the current attack surface is zero, any future introduction of features without these fundamental security checks could expose the plugin to a wide range of attacks, particularly if new AJAX handlers, REST API routes, or shortcodes are added. The lack of taint analysis data also makes it impossible to assess the security of any potential data flows within the plugin, leaving a blind spot in the analysis.

In conclusion, the plugin is currently in a very secure state with excellent coding practices observed in the analyzed code. The lack of historical vulnerabilities further bolsters this confidence. The primary weakness lies in the absence of foundational security mechanisms like nonce and capability checks, which, if unaddressed, could become a major security risk with any future development. The current lack of observable risks is a strength, but the potential for future issues due to missing security checks is a notable weakness.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Limited output escaping (13% unescaped)
  • No taint analysis data available
Vulnerabilities
None known

Global threat activity level Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Global threat activity level Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
52 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

87% escaped60 total outputs
Attack Surface

Global threat activity level Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filterwp_feed_cache_transient_lifetimespywarethreatswidget.php:80
actionwidgets_initspywarethreatswidget.php:384
actioninitspywarethreatswidget.php:450
filterwp_feed_cache_transient_lifetimetrunk\spywarethreatswidget.php:80
actionwidgets_inittrunk\spywarethreatswidget.php:384
actioninittrunk\spywarethreatswidget.php:450
Maintenance & Trust

Global threat activity level Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 23, 2026
PHP min version7.3
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Global threat activity level Widget Developer Profile

pcrisk

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Global threat activity level Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/global-threat-activity-level-widget/spywarethreatswidget.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Global threat activity level Widget