
IssueM Security & Risk Analysis
wordpress.org/plugins/issuemCreate, Organize, and Publish Issues with WordPress
Is IssueM Safe to Use in 2026?
Generally Safe
Score 99/100IssueM has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "issuem" plugin v2.9.1 presents a generally positive security posture with several good practices evident. The plugin has a limited attack surface with all identified entry points secured by either authentication or capability checks. The static analysis also indicates a high percentage of properly escaped output and a decent number of nonce checks, suggesting an awareness of common web security vulnerabilities. Furthermore, the absence of dangerous functions, file operations, and critical or high severity taint flows are strong indicators of secure coding practices.
However, there are a few areas of concern. The significant finding of 100% of SQL queries not using prepared statements is a critical risk. This lack of prepared statements makes the plugin susceptible to SQL injection vulnerabilities, especially if any user-supplied data is being used within these queries. Additionally, the presence of a past medium severity Cross-site Scripting (XSS) vulnerability, even if patched, highlights a historical weakness that warrants vigilance. While no current unpatched CVEs or critical taint flows are present, the identified SQL query pattern and historical vulnerability type indicate potential areas for future exploitation if not addressed or monitored.
In conclusion, the "issuem" plugin v2.9.1 demonstrates good security hygiene in many areas, particularly regarding its attack surface and output escaping. However, the complete lack of prepared statements for SQL queries represents a substantial risk that requires immediate attention. The history of an XSS vulnerability, while resolved, serves as a reminder to maintain a proactive security approach. Addressing the SQL query issue would significantly strengthen the plugin's overall security.
Key Concerns
- SQL queries not using prepared statements
- Past medium severity XSS vulnerability
IssueM Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
IssueM <= 2.9.0 - Authenticated (Author+) Stored Cross-Site Scripting
IssueM Release Timeline
IssueM Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
IssueM Attack Surface
AJAX Handlers 1
Shortcodes 5
WordPress Hooks 49
Scheduled Events 1
Maintenance & Trust
IssueM Maintenance & Trust
Maintenance Signals
Community Trust
IssueM Alternatives
News Manager
news-manager
Every CMS site needs a news section. News Manager allows you add, manage and display news, date archives, AJAX Calendar, Categories, Tags and more.
Project Management, Bug and Issue Tracking Plugin – Software Issue Manager
software-issue-manager
Best issue tracking, bug tracking and project management plugin. Easily manage tasks, stay organized, and track progress in WordPress.
Manage Issue Based Magazine (Multi-language)
manage-issue-based-magazine
Transform your website from a boring blog into a mesmerizing magazine in your language.
IssueM Developer Profile
2 plugins · 1K total installs
How We Detect IssueM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/issuem/issuem.css/wp-content/plugins/issuem/js/issuem-admin.js/wp-content/plugins/issuem/js/issuem-frontend.js/wp-content/plugins/issuem/js/issuem-colorbox.js/wp-content/plugins/issuem/issuem.css/wp-content/plugins/issuem/js/issuem-admin.js/wp-content/plugins/issuem/js/issuem-frontend.js/wp-content/plugins/issuem/js/issuem-colorbox.jsissuem/issuem.css?ver=issuem/js/issuem-admin.js?ver=issuem/js/issuem-frontend.js?ver=issuem/js/issuem-colorbox.js?ver=HTML / DOM Fingerprints
issuem-settings-wrapissuem-help-wrapdata-notice="rss_item"data-type="dismiss"window.issuem_settings[issuem_cover][issuem_recent][issuem_archive][issuem_specific_issue]