
Google Knowledge Phone Number Security & Risk Analysis
wordpress.org/plugins/google-knowledge-phone-numberAdd JSON-LD markup in your WordPress website, to display your company's phone number(s) on Google Knowledge Panels.
Is Google Knowledge Phone Number Safe to Use in 2026?
Generally Safe
Score 100/100Google Knowledge Phone Number has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "google-knowledge-phone-number" plugin version 1.0.2 presents a mixed security profile. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and its static analysis indicates a very small attack surface, with no discovered AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no external HTTP requests, file operations, or bundled libraries, which minimizes common attack vectors. However, significant concerns arise from the code quality signals. The presence of `create_function`, which is deprecated and considered a security risk, alongside 100% of SQL queries not using prepared statements, indicates a high potential for vulnerabilities like SQL injection. The extremely low percentage of properly escaped output (14%) also points to a significant risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks further exacerbates these risks, leaving any potential entry points highly vulnerable to unauthorized actions and data manipulation.
While the plugin's lack of history might suggest a safe past, the current code analysis reveals significant weaknesses that could lead to future vulnerabilities. The absence of documented CVEs is a positive aspect, but it doesn't mitigate the inherent risks identified in the code. The plugin's strengths lie in its limited attack surface and lack of external dependencies. Conversely, its weaknesses are substantial, centered around insecure coding practices in database interactions and output handling, coupled with a complete absence of common WordPress security checks. A balanced conclusion is that while the plugin is currently unexploited, its underlying code quality makes it a high risk for future exploitation.
Key Concerns
- Dangerous function create_function used
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Google Knowledge Phone Number Security Vulnerabilities
Google Knowledge Phone Number Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Google Knowledge Phone Number Attack Surface
WordPress Hooks 6
Maintenance & Trust
Google Knowledge Phone Number Maintenance & Trust
Maintenance Signals
Community Trust
Google Knowledge Phone Number Alternatives
Schema – All In One Schema Rich Snippets
all-in-one-schemaorg-rich-snippets
Improve SEO, elevate rankings and Boost CTR. Supports different types of content and works well with Google, Bing, Yahoo, and Facebook.
Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event
event-schema
Automatically generate Google Event Rich Snippet Schema (JSON-LD) for events using popular calendar plugins.
The SEO Rich Snippets
the-seo-rich-snippets
The SEO Rich Snippets for home page review website.
SEO Recipe Snippets
recipe-snippets
Show recipe snippets on Google search results.
Ai1ec Rich Snippets
rich-snippet-for-ai1ec
Make your All-in-One Event Calendar events more discoverable in Google (and other) search results by adding rich snippets to them.
Google Knowledge Phone Number Developer Profile
4 plugins · 2.0M total installs
How We Detect Google Knowledge Phone Number
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.