
Google+ Plus WordPress Widget Security & Risk Analysis
wordpress.org/plugins/google-wordpress-widgetsDisplay updates/post from one or more Google+ Plus accounts a WordPress widget. Included QR code for Google+ Profile.
Is Google+ Plus WordPress Widget Safe to Use in 2026?
Generally Safe
Score 85/100Google+ Plus WordPress Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "google-wordpress-widgets" plugin v5.0 appears to have a generally good security posture. The absence of any known CVEs and the complete lack of critical or high-severity vulnerabilities in its history suggest a commitment to security or a fortunate lack of past exploits. The code analysis further supports this with a clean slate regarding dangerous functions, raw SQL queries, and taint analysis, indicating sound development practices in these areas.
However, there are notable areas for concern. The complete lack of nonce checks and capability checks across all entry points (AJAX, REST API, shortcodes, cron) presents a significant risk. This means that any functionality exposed through these methods could potentially be triggered by unauthenticated or unauthorized users. While the static analysis found no direct vulnerabilities in these entry points, the absence of security checks is a fundamental weakness that could be exploited if any logic flaws are introduced in the future or if the plugin's functionality expands.
Furthermore, the plugin's external HTTP requests, while not inherently a vulnerability, introduce an external dependency that could be a vector for supply chain attacks or lead to issues if the external service is compromised or unavailable. The 54% proper output escaping also indicates that nearly half of the output is not properly sanitized, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without sanitization. The conclusion is that while the plugin has avoided known vulnerabilities, the lack of fundamental security checks on its entry points and the concerning output escaping percentage represent significant potential risks that should be addressed.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Significant portion of output unescaped
- External HTTP requests present
Google+ Plus WordPress Widget Security Vulnerabilities
Google+ Plus WordPress Widget Code Analysis
Output Escaping
Google+ Plus WordPress Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Google+ Plus WordPress Widget Maintenance & Trust
Maintenance Signals
Community Trust
Google+ Plus WordPress Widget Alternatives
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Maps Widget for Google Maps
google-maps-widget
Are your Google Maps slow? Try Map Widget for Google Maps. You'll have a fast Google Maps widget with a thumbnail & lightbox map in minutes!
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
Google+ Plus WordPress Widget Developer Profile
8 plugins · 170 total installs
How We Detect Google+ Plus WordPress Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_google_plusauthor-boxplus_personplusError: Please make sure the Google account is <a href="http://plus.google.com/">public</a>.Error: Google Plus did not respond. Please wait a few minutes and refresh this page.name ='plus_avatar'document.plus_avatar.srchttps://www.googleapis.com/plus/v1/people/