
iChart – Easy Charts and Graphs Security & Risk Analysis
wordpress.org/plugins/ichartCreate Responsive Charts and graphs iChart! COVID-19 widget for Live Data. Sidebar ticker Widget for CORONA stats. Add beautiful graphs & charts t …
Is iChart – Easy Charts and Graphs Safe to Use in 2026?
Generally Safe
Score 99/100iChart – Easy Charts and Graphs has a strong security track record. Known vulnerabilities have been patched promptly.
The "ichart" v2.1.4 plugin exhibits a generally good security posture with several positive indicators. Notably, there are no identified taint flows, no dangerous functions used, and all SQL queries are properly prepared. The plugin also incorporates a commendable number of capability checks and nonce checks, contributing to a robust defense against common attacks. Furthermore, the absence of unpatched CVEs in its history is a strong positive sign, suggesting active maintenance and prompt security patching.
However, the plugin's static analysis does reveal some areas for improvement. While the overall output escaping is at 78%, this still leaves 22% of outputs potentially unescaped, which could present a cross-site scripting (XSS) risk, especially given that XSS has been a historical vulnerability type for this plugin. The presence of two external HTTP requests also warrants attention, as these can sometimes be exploited if not handled securely. The plugin's vulnerability history, while currently clean, did include a past medium-severity vulnerability related to improper neutralization of input, reinforcing the need for vigilant output sanitization.
In conclusion, "ichart" v2.1.4 demonstrates strong foundational security practices, particularly in its handling of SQL and authentication. The primary concern lies in the potential for unescaped output, a historical weakness that should be addressed to mitigate XSS risks. Continued vigilance regarding external requests and ongoing monitoring of its vulnerability history will be crucial for maintaining its security.
Key Concerns
- Unescaped output exists (22%)
- Past medium vulnerability (XSS)
- External HTTP requests (2)
iChart – Easy Charts and Graphs Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
iChart – Easy Charts and Graphs <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter
iChart – Easy Charts and Graphs Code Analysis
Bundled Libraries
Output Escaping
iChart – Easy Charts and Graphs Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 26
Scheduled Events 1
Maintenance & Trust
iChart – Easy Charts and Graphs Maintenance & Trust
Maintenance Signals
Community Trust
iChart – Easy Charts and Graphs Alternatives
Visualizer: Tables and Charts Manager for WordPress
visualizer
A simple yet powerful WordPress chart plugin to effortlessly create and embed responsive charts & tables into your site, supporting multiple data …
Graphina – Charts and Graphs For Elementor
graphina-elementor-charts-and-graphs
Most Powerful Data visualization plugin for WordPress Elementor. The easiest way to build gorgeous Charts & Graphs on your Elementor website.
Chartify – WordPress Chart Plugin
chart-builder
Chartify is a powerful WordPress Chart Builder Plugin that will help you to create WordPress Graphs & Charts easily and quickly.
M Chart
m-chart
Manage data sets and display them as charts in WordPress.
UberChart – WordPress Chart Plugin
daext-uberchart
UberChart brings the endless customization possibilities included in the Chart.js library to WordPress.
iChart – Easy Charts and Graphs Developer Profile
29 plugins · 26K total installs
How We Detect iChart – Easy Charts and Graphs
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ichart/assets/js/chart.js/wp-content/plugins/ichart/assets/js/chartjs-plugin-deferred.js/wp-content/plugins/ichart/assets/css/chart-field.css/wp-content/plugins/ichart/assets/js/custom-color_picker.js/wp-content/plugins/ichart/assets/js/chart-field.js/wp-content/plugins/ichart/assets/js/qcld-tinymce-iChart.js/wp-content/plugins/ichart/gutenberg/ichart-block/dist/blocks.style.build.css/wp-content/plugins/ichart/gutenberg/ichart-block/dist/blocks.build.js+1 more/wp-content/plugins/ichart/assets/js/chart.js/wp-content/plugins/ichart/assets/js/chartjs-plugin-deferred.js/wp-content/plugins/ichart/assets/js/custom-color_picker.js/wp-content/plugins/ichart/assets/js/chart-field.js/wp-content/plugins/ichart/assets/js/qcld-tinymce-iChart.js/wp-content/plugins/ichart/gutenberg/ichart-block/dist/blocks.build.jsHTML / DOM Fingerprints
qcld-chart-field-cssqcld-custom-script-handleqcld-custom-script-iChartichart_block-cgb-style-cssichart_block-cgb-block-editor-cssid="ichart_shortcode_generator_meta"qcld_ichart_url1qcld_ichart_img_url1qcld_ichart_asset_url1qcichart_upgrade_linkqcld_ichart_dirichart_block_cgb_block_js