
Gravitation Portfolios Security & Risk Analysis
wordpress.org/plugins/gravitation-portfoliosA Plugin to integrate portfolios
Is Gravitation Portfolios Safe to Use in 2026?
Generally Safe
Score 85/100Gravitation Portfolios has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'gravitation-portfolios' v1.0.0 plugin presents a generally good security posture with some notable areas for improvement. Its limited attack surface, with only one shortcode and no unprotected entry points, is a significant strength. The complete absence of raw SQL queries and the consistent use of prepared statements for database interactions are excellent practices. Furthermore, the plugin incorporates nonce and capability checks, indicating an awareness of common WordPress security vulnerabilities. The vulnerability history is clean, with no recorded CVEs, which is a positive indicator of past development quality.
However, a critical concern arises from the low percentage of properly escaped output. With 112 total outputs and only 16% properly escaped, there is a high likelihood of cross-site scripting (XSS) vulnerabilities. Any user-supplied data that is displayed without proper sanitization could be exploited by an attacker to inject malicious scripts. The inclusion of the Select2 library, while potentially useful, also introduces a risk if it's an outdated version, as bundled libraries can be vectors for vulnerabilities if not maintained.
In conclusion, while 'gravitation-portfolios' v1.0.0 demonstrates strengths in limiting its attack surface and securing database interactions, the significant lack of output escaping represents a substantial security risk that requires immediate attention. Addressing this output sanitization issue is paramount to improving the plugin's overall security.
Key Concerns
- Insufficient output escaping
- Bundled library (Select2) potentially outdated
Gravitation Portfolios Security Vulnerabilities
Gravitation Portfolios Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Gravitation Portfolios Attack Surface
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Gravitation Portfolios Maintenance & Trust
Maintenance Signals
Community Trust
Gravitation Portfolios Alternatives
Theme Demo Importer and Patterns Library for CozyThemes – Cozy Essential Addons
cozy-essential-addons
Cozy Essential Addons is the free WordPress plugin for Custom post type and provides basic skeletal for custom post type list.
Portfolios
portfolios
Adds a "Portfolio Item" custom post type with associated "Portfolio" and "Porfolio Tag" taxonomies.
CB Portfolio Work For Elementor
cb-portfolio-work
Show your works history as a portfolio on your website by using elementor widget or shortcode [cb-pwork-our-works]
Gravitation Portfolios Developer Profile
5 plugins · 50 total installs
How We Detect Gravitation Portfolios
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gravitation-portfolios/css/portfolio-styles.css/wp-content/plugins/gravitation-portfolios/js/jquery.easing.1.3.js/wp-content/plugins/gravitation-portfolios/js/jquery.quicksand.js/wp-content/plugins/gravitation-portfolios/js/functions.js/wp-content/plugins/gravitation-portfolios/js/jquery.easing.1.3.js/wp-content/plugins/gravitation-portfolios/js/jquery.quicksand.js/wp-content/plugins/gravitation-portfolios/js/functions.jsgravitation_portfolios_style?ver=gravitation_portfolios_easing?ver=gravitation_portfolios_quicksand?ver=gravitation_portfolios_functions?ver=HTML / DOM Fingerprints
gravitation-portfolios-itemgravitation-portfolio-titlegravitation-portfolio-category<!-- Gravitation portfoliosCopyright (C) 2016 Gravitation portfoliosThis library is free software; you can redistribute it and/ormodify it under the terms of the GNU Lesser General Public+27 moredata-filterdata-idjQuery(document).readyjQuery().quicksand[gravitation_portfolios ids="