Hikari Unicornified Gravatars Security & Risk Analysis

wordpress.org/plugins/hikari-unicornified-gravatars

Hikari Unicornified Gravatars converts avatars from people that don't have a Gravatar, into customized unicorns.

10 active installs v0.00.02 PHP + WP 2.8.0+ Updated Apr 9, 2010
avatarcommentcommentsgravatarunicorn
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hikari Unicornified Gravatars Safe to Use in 2026?

Generally Safe

Score 85/100

Hikari Unicornified Gravatars has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The "hikari-unicornified-gravatars" plugin v0.00.02 presents a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and does not appear to perform any external HTTP requests or file operations. All detected SQL queries are properly prepared, which is a significant security best practice. However, the static analysis reveals substantial concerns, particularly regarding output escaping and taint analysis. A mere 2% of output escaping is properly done, indicating a high risk of cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis shows two flows with unsanitized paths, suggesting potential security weaknesses that could be exploited if they lead to sensitive operations. The complete lack of nonce checks and capability checks across all identified entry points (even though the attack surface is reported as zero) is also a serious oversight, as it leaves any potential future additions to the plugin vulnerable to CSRF and unauthorized actions. The vulnerability history being clear is a good sign, but it doesn't mitigate the identified code-level risks.

Key Concerns

  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
  • No nonce checks detected
  • No capability checks detected
Vulnerabilities
None known

Hikari Unicornified Gravatars Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hikari Unicornified Gravatars Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
53
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

2% escaped54 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
debugRequestParameters (hikari-tools.php:732)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Hikari Unicornified Gravatars Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedhikari-tools.php:33
actionadmin_inithikari-tools.php:292
actionadmin_menuhikari-tools.php:293
filterget_avatarhikari-unicornified-gravatar-core.php:21
Maintenance & Trust

Hikari Unicornified Gravatars Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedApr 9, 2010
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Hikari Unicornified Gravatars Developer Profile

shidouhikari

6 plugins · 350 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hikari Unicornified Gravatars

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hikari-unicornified-gravatars/hikari-unicornified-gravatar.php

HTML / DOM Fingerprints

HTML Comments
Copyright Hikari (http://wordpress.Hikari.ws), 2010
FAQ

Frequently Asked Questions about Hikari Unicornified Gravatars