
GW Info Box Security & Risk Analysis
wordpress.org/plugins/gw-info-boxDisplay live WordPress.org plugin information in a clean, styled box – using a simple shortcode.
Is GW Info Box Safe to Use in 2026?
Generally Safe
Score 100/100GW Info Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gw-info-box" v1.1.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of critical or high-severity issues in its vulnerability history is a significant positive indicator, suggesting a mature and well-maintained codebase. The code analysis reveals a commendably low attack surface, with no unprotected AJAX handlers or REST API routes. Furthermore, all detected SQL queries utilize prepared statements, and a very high percentage of output is properly escaped, minimizing the risk of cross-site scripting (XSS) vulnerabilities. The lack of file operations and external HTTP requests also reduces potential attack vectors.
However, there are a few areas that warrant attention and suggest a slightly less robust security implementation. The plugin relies on shortcodes as its primary entry points, and while there are no explicit capability checks or nonce checks mentioned for these, the lack of direct data sanitization in the taint analysis (which showed 0 flows) combined with the limited attack surface might be the reason for this absence. It's important to note that the static analysis did not detect any dangerous functions, which is a good sign.
In conclusion, the plugin is relatively secure, with no known critical vulnerabilities and good practices in SQL and output sanitization. The primary area for improvement would be to explicitly implement capability checks and nonces for its shortcode functionalities, even with a limited attack surface, to further harden the plugin against potential future threats or unexpected usage patterns.
Key Concerns
- Missing nonce checks on shortcodes
- Missing capability checks on shortcodes
GW Info Box Security Vulnerabilities
GW Info Box Code Analysis
Output Escaping
GW Info Box Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
GW Info Box Maintenance & Trust
Maintenance Signals
Community Trust
GW Info Box Alternatives
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Export Plugin Details
export-plugin-details
Simple way to export your installed plugins list in CSV format.
Menu In Post
menu-in-post
A simple but flexible plugin to allow the use of menus in posts and pages.
WebMan Amplifier
webman-amplifier
Amplifies functionality of WP themes. Provides custom post types, shortcodes, metaboxes, icons. Theme developer's best friend!
Last Updated Shortcode
last-updated-shortcode
Creates a shortcode to display the date/time when a post/page was last updated (with optional formatting).
GW Info Box Developer Profile
4 plugins · 200 total installs
How We Detect GW Info Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gw-info-box/includes/styles.cssgw-info-box/includes/styles.css?ver=HTML / DOM Fingerprints
gw-info-containergw-info-boxgw-rowgw-labelgw-starsdata-slug<div class="gw-info-container"<div class="gw-info-box"<img src="https://ps.w.org/<a href="https://wordpress.org/plugins/