
IG Portfolio Security & Risk Analysis
wordpress.org/plugins/ig-portfolioIG Portfolio is a clean and easy-to-use portfolio plugin for WordPress.
Is IG Portfolio Safe to Use in 2026?
Generally Safe
Score 85/100IG Portfolio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ig-portfolio plugin v2.4 exhibits a generally good security posture with no known CVEs and a strong adherence to using prepared statements for SQL queries. The plugin also demonstrates a good practice of implementing capability checks for its entry points. However, the presence of the 'unserialize' function, despite no immediate taint flow issues detected, poses a potential risk if user-controlled data is ever passed to it without proper sanitization. Furthermore, the report indicates that a significant portion of output (49%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped output contains malicious user input. The limited attack surface of only two shortcodes and no unprotected AJAX or REST API routes is a positive sign, but the lack of taint analysis data is a notable gap in understanding the full security landscape. Overall, while the plugin has strong foundations in some areas, the identified risks related to unserialize and unescaped output warrant attention for a more robust security profile.
Key Concerns
- Dangerous function 'unserialize' present
- Nearly half of outputs are not properly escaped
IG Portfolio Security Vulnerabilities
IG Portfolio Release Timeline
IG Portfolio Code Analysis
Dangerous Functions Found
Output Escaping
IG Portfolio Attack Surface
Shortcodes 2
WordPress Hooks 19
Maintenance & Trust
IG Portfolio Maintenance & Trust
Maintenance Signals
Community Trust
IG Portfolio Alternatives
Automatik Blog
automatik-blog
A plugin for integration with Automatik Blog, allowing automated publishing of SEO-optimized articles via REST API.
Bulk Images to Posts
bulk-images-to-posts
Bulk upload images to automatically create posts / custom posts with featured images.
Fullscreen Galleria
fullscreen-galleria
A simple fullscreen gallery to Wordpress
Easy p5.js Block
easy-p5-js-block
Adds a Gutenberg block to easily add custom p5.js code in your pages and preview it as you edit.
Portfolio CPT
portfolio-cpt
Enables a 'Portfolio' type and 'Portfolio Tags' taxonomy.
IG Portfolio Developer Profile
4 plugins · 160 total installs
How We Detect IG Portfolio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ig-portfolio/ig-portfolio.css/wp-content/plugins/ig-portfolio/welcome/css/welcome.css/wp-content/plugins/ig-portfolio/includes/mce-button.jsHTML / DOM Fingerprints
ig-potfolio-pageig-portfolioig-portfolio-gallerygallery-projectgallery-imagedata-mce-btndata-mce-grpig_portfolio_mce_button<div class="ig-potfolio-page"><div id="project-<div class="image <div class="title">