Google Knowledge Phone Number Security & Risk Analysis

wordpress.org/plugins/google-knowledge-phone-number

Add JSON-LD markup in your WordPress website, to display your company's phone number(s) on Google Knowledge Panels.

10 active installs v1.0.2 PHP + WP 3.5.1+ Updated Unknown
googleknowledge-graphphone-numberrich-snippetsseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Google Knowledge Phone Number Safe to Use in 2026?

Generally Safe

Score 100/100

Google Knowledge Phone Number has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "google-knowledge-phone-number" plugin version 1.0.2 presents a mixed security profile. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and its static analysis indicates a very small attack surface, with no discovered AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, there are no external HTTP requests, file operations, or bundled libraries, which minimizes common attack vectors. However, significant concerns arise from the code quality signals. The presence of `create_function`, which is deprecated and considered a security risk, alongside 100% of SQL queries not using prepared statements, indicates a high potential for vulnerabilities like SQL injection. The extremely low percentage of properly escaped output (14%) also points to a significant risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks further exacerbates these risks, leaving any potential entry points highly vulnerable to unauthorized actions and data manipulation.

While the plugin's lack of history might suggest a safe past, the current code analysis reveals significant weaknesses that could lead to future vulnerabilities. The absence of documented CVEs is a positive aspect, but it doesn't mitigate the inherent risks identified in the code. The plugin's strengths lie in its limited attack surface and lack of external dependencies. Conversely, its weaknesses are substantial, centered around insecure coding practices in database interactions and output handling, coupled with a complete absence of common WordPress security checks. A balanced conclusion is that while the plugin is currently unexploited, its underlying code quality makes it a high risk for future exploitation.

Key Concerns

  • Dangerous function create_function used
  • SQL queries not using prepared statements
  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Google Knowledge Phone Number Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Google Knowledge Phone Number Code Analysis

Dangerous Functions
1
Raw SQL Queries
3
0 prepared
Unescaped Output
6
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_function$callback = create_function('', 'echo "'.str_replace('"', '\"', $section['desc']).'";');includes\class.settings-api.php:112

SQL Query Safety

0% prepared3 total queries

Output Escaping

14% escaped7 total outputs
Attack Surface

Google Knowledge Phone Number Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuadmin\gkpn-admin.php:68
actionadmin_initadmin\gkpn-admin.php:80
actionplugins_loadedgoogle-knowledge-phone-number.php:43
actionplugins_loadedgoogle-knowledge-phone-number.php:52
actioninitpublic\class-gkpn.php:67
actionwp_footerpublic\class-gkpn.php:72
Maintenance & Trust

Google Knowledge Phone Number Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Google Knowledge Phone Number Developer Profile

Remy Perona

4 plugins · 2.0M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
1211 days
View full developer profile
Detection Fingerprints

How We Detect Google Knowledge Phone Number

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Google Knowledge Phone Number