Spring Security & Risk Analysis

wordpress.org/plugins/gospring

use this plugin to embed GoSpring.ai quiz in your wordpress site.

10 active installs v6.0 PHP 7.0+ WP 5.9+ Updated Sep 5, 2022
blockquestionnairequizquiz-makertest
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spring Safe to Use in 2026?

Generally Safe

Score 85/100

Spring has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "gospring" v6.0 plugin exhibits a strong security posture based on the provided static analysis results. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code analysis indicates robust security practices with no dangerous functions, all SQL queries utilizing prepared statements, and all outputs being properly escaped. The lack of file operations, external HTTP requests, nonce checks, capability checks, and bundled libraries further contributes to this positive assessment.

The plugin also boasts a clean vulnerability history, with no known CVEs or recorded vulnerability types. This suggests a proactive approach to security by the developers or a history of minimal exposure. The taint analysis also reveals no identified flows with unsanitized paths, indicating no immediate risks of data injection or manipulation through the analyzed code paths.

In conclusion, the "gospring" v6.0 plugin appears to be well-secured. The comprehensive absence of common vulnerabilities and a limited attack surface are significant strengths. While the data suggests a very low risk, it's important to remember that static analysis is not exhaustive and dynamic testing or code review by a security professional would provide a more definitive assurance. However, based on the provided metrics, this plugin demonstrates good security hygiene.

Vulnerabilities
None known

Spring Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Spring Release Timeline

v6.0Current
v5.0
v1.0
v0.1.0
Code Analysis
Analyzed Mar 16, 2026

Spring Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Spring Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitnpblock.php:30
Maintenance & Trust

Spring Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 5, 2022
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Spring Developer Profile

aashish512

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spring

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gospring/build/index.js/wp-content/plugins/gospring/build/index.css
Script Paths
/wp-content/plugins/gospring/build/index.js
Version Parameters
gospring/build/index.js?ver=gospring/build/index.css?ver=

HTML / DOM Fingerprints

Shortcode Output
<!-- wp:gospring/npblock -->
FAQ

Frequently Asked Questions about Spring