Igreen Alexa Site Rank Security & Risk Analysis

wordpress.org/plugins/igreen-alexa-site-rank

Get your updated ALEXA RANK in widgets or integrate in theme using plugin API/ shortcode.You can display your page rank anywhere in your blog

10 active installs v4.0.0 PHP + WP 3.0+ Updated Sep 20, 2015
alexa-apialexa-rankalexa-rank-widgetsseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Igreen Alexa Site Rank Safe to Use in 2026?

Generally Safe

Score 85/100

Igreen Alexa Site Rank has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The igreen-alexa-site-rank v4.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates excellent practices in handling database queries, with 100% of SQL queries using prepared statements, and it does not appear to make any external HTTP requests or bundle external libraries, which reduces the attack surface from third-party code. The lack of recorded CVEs and common vulnerability types in its history suggests a reasonably secure past, implying developers have addressed issues promptly or that the plugin hasn't been a significant target.

However, several concerns arise from the static analysis. The presence of the `create_function` function is a significant red flag, as it is deprecated and can lead to security vulnerabilities if used with user-supplied input due to its eval-like behavior. Furthermore, the plugin shows a very low rate of output escaping (17%), which is a critical weakness. This means user-controlled data displayed on the frontend is highly susceptible to Cross-Site Scripting (XSS) attacks. The taint analysis revealing unsanitized paths in all analyzed flows, even if not rated as critical or high severity in this specific instance, highlights a systemic issue in how data is handled, making it easier for an attacker to exploit the unescaped output.

In conclusion, while the plugin has strengths in its database interaction and a clean vulnerability history, the identified issues with `create_function` and particularly the widespread lack of output escaping pose significant risks, especially for XSS vulnerabilities. The taint analysis, though not yielding critical findings here, reinforces the concern about data sanitization.

Key Concerns

  • Unsanitized path taint flows
  • Low output escaping rate
  • Dangerous function create_function used
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Igreen Alexa Site Rank Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Igreen Alexa Site Rank Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
10
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'widgets_init', create_function( '', 'register_widget( "Igreen_Alexa_Widget" );' ) );index.php:124

Output Escaping

17% escaped12 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
widget (index.php:70)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Igreen Alexa Site Rank Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ALEXARANK] index.php:14
WordPress Hooks 2
actionwidgets_initindex.php:124
actionwp_dashboard_setupindex.php:340
Maintenance & Trust

Igreen Alexa Site Rank Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 20, 2015
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Igreen Alexa Site Rank Developer Profile

susheelhbti

14 plugins · 40 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Igreen Alexa Site Rank

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
Alexa Rank of
FAQ

Frequently Asked Questions about Igreen Alexa Site Rank