
Kblog Include Security & Risk Analysis
wordpress.org/plugins/kblog-includeTranscludes content from arXiv and other academic repositories.
Is Kblog Include Safe to Use in 2026?
Generally Safe
Score 100/100Kblog Include has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kblog-include" plugin version 0.1 exhibits a generally good security posture based on the provided static analysis. The code demonstrates a commitment to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping all outputs. The absence of dangerous functions, file operations, and taint analysis findings further strengthens this positive assessment. Furthermore, there is no recorded vulnerability history, suggesting a lack of publicly known or previously exploited issues.
Despite these strengths, there are areas that warrant caution. The plugin lacks explicit capability checks and nonce verification for its single shortcode entry point. While the attack surface is small, this omission could potentially expose the shortcode's functionality to unauthorized use or manipulation if it performs sensitive actions or relies on user-provided input that isn't otherwise validated or sanitized within the shortcode's callback. The presence of external HTTP requests also introduces a minor risk if these requests are not handled with robust error checking and validation of the responses, though the static analysis did not identify any specific issues in this regard.
In conclusion, "kblog-include" v0.1 appears to be a well-coded plugin with no critical security flaws identified. Its strengths lie in its clean SQL handling and output escaping. However, the lack of authentication and authorization checks on its shortcode represents a potential weakness that could be exploited in certain scenarios. The absence of historical vulnerabilities is a positive indicator, but it does not negate the need for careful review of the shortcode's implementation.
Key Concerns
- Missing capability check on shortcode
- Missing nonce check on shortcode
Kblog Include Security Vulnerabilities
Kblog Include Code Analysis
Output Escaping
Kblog Include Attack Surface
Shortcodes 1
Maintenance & Trust
Kblog Include Maintenance & Trust
Maintenance Signals
Community Trust
Kblog Include Alternatives
Kblog Metadata
kblog-metadata
Displays bibliographic metadata both for humans and computers.
Scholar Publications Fetcher
scholar-publications-fetcher
A lightweight and high-performance plugin to fetch, cache, and display your Google Scholar publications in a clean, modern, and responsive card layout …
PubMed Posts
pubmed-posts
This plugin adds a dashboard widget that creates posts from PubMed articles, plus a search widget that finds posts with specific article data.
MathJax-LaTeX
mathjax-latex
This plugin enables MathJax (http://www.mathjax.org) functionality for WordPress (http://www.wordpress.org).
Zotpress
zotpress
Zotpress displays your Zotero citations on WordPress.
Kblog Include Developer Profile
2 plugins · 20 total installs
How We Detect Kblog Include
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
serverservernamekblog_includekblog_oai_pmhkblog_include_add_serverkblog_include_add_oai_server<strong>Server not known:Exception!!!: