Jarvis Security & Risk Analysis

wordpress.org/plugins/jarvis

Jarvis is your admin assistant, putting WordPress at your fingertips via a quicksearch interface.

600 active installs v1.1.1 PHP + WP 4.8+ Updated Nov 1, 2023
jarvislaunchbarpagespostssearch
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Jarvis Safe to Use in 2026?

Generally Safe

Score 85/100

Jarvis has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "jarvis" v1.1.1 plugin exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed, resulting in a zero attack surface. The code signals indicate excellent practices, with all SQL queries using prepared statements, a high percentage of output escaping, and appropriate use of nonce and capability checks. The absence of file operations and external HTTP requests further mitigates common attack vectors. Taint analysis reveals no unsanitized flows, suggesting the plugin is not vulnerable to typical injection attacks.

The vulnerability history is also clean, with zero known CVEs recorded. This lack of past vulnerabilities, combined with the positive static analysis, suggests a well-developed and secure plugin. The plugin's strengths lie in its minimal attack surface and robust internal security checks. While the presence of bundled jQuery is noted, it's a common library and the analysis doesn't indicate any specific issues with its integration or version.

Overall, "jarvis" v1.1.1 appears to be a very secure plugin. The data provided shows a deliberate effort to implement secure coding practices and a clean security track record. There are no immediate red flags or significant risks identified based on this analysis.

Vulnerabilities
None known

Jarvis Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Jarvis Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
1
16 escaped
Nonce Checks
1
Capability Checks
12
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery

SQL Query Safety

100% prepared4 total queries

Output Escaping

94% escaped17 total outputs
Attack Surface

Jarvis Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_bar_menusrc\php\plugin.php:127
actionadmin_enqueue_scriptssrc\php\plugin.php:128
actionadmin_initsrc\php\plugin.php:129
actionedit_user_profile_updatesrc\php\plugin.php:130
actionedit_user_profilesrc\php\plugin.php:131
actionpersonal_options_updatesrc\php\plugin.php:132
actionrest_api_initsrc\php\plugin.php:133
actionshow_user_profilesrc\php\plugin.php:134
actionadmin_bar_menusrc\Plugin.php:88
actionadmin_enqueue_scriptssrc\Plugin.php:89
actionadmin_initsrc\Plugin.php:90
actionedit_user_profile_updatesrc\Plugin.php:91
actionedit_user_profilesrc\Plugin.php:92
actionpersonal_options_updatesrc\Plugin.php:93
actionrest_api_initsrc\Plugin.php:94
actionshow_user_profilesrc\Plugin.php:95
filteradmin_body_classsrc\Plugin.php:96
Maintenance & Trust

Jarvis Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedNov 1, 2023
PHP min version
Downloads21K

Community Trust

Rating98/100
Number of ratings13
Active installs600
Developer Profile

Jarvis Developer Profile

WDG

1 plugin · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Jarvis

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jarvis/dist/css/jarvis.css/wp-content/plugins/jarvis/dist/js/jarvis.js
Script Paths
/wp-content/plugins/jarvis/dist/js/jarvis.js
Version Parameters
jarvis/dist/css/jarvis.css?ver=jarvis/dist/js/jarvis.js?ver=

HTML / DOM Fingerprints

CSS Classes
jarvis-searchjarvis-main
HTML Comments
<!-- Jarvis Admin Bar Menu --><!-- Jarvis -->
Data Attributes
data-jarvis-hotkeydata-jarvis-themedata-jarvis-noncedata-jarvis-searchurl
JS Globals
jarvis
REST Endpoints
/wp-json/jarvis/v1/search/
FAQ

Frequently Asked Questions about Jarvis