
Kblog Metadata Security & Risk Analysis
wordpress.org/plugins/kblog-metadataDisplays bibliographic metadata both for humans and computers.
Is Kblog Metadata Safe to Use in 2026?
Generally Safe
Score 85/100Kblog Metadata has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The kblog-metadata plugin v0.6 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, implementing nonce checks on all identified entry points (shortcodes), and performing capability checks on most interactions. The absence of known CVEs and a clean vulnerability history further suggests a generally well-maintained codebase.
However, a significant concern lies in the complete lack of output escaping for any of the 25 identified output points. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data, if not properly sanitized before display, could be injected and executed in the user's browser. Additionally, the presence of one flow with an unsanitized path in the taint analysis, even without a critical or high severity, warrants further investigation as it could potentially lead to unexpected behavior or security issues.
While the plugin has a solid foundation with respect to SQL and authentication checks, the critical deficiency in output escaping presents a substantial security risk. The absence of past vulnerabilities could be due to the plugin's limited adoption or simply a lack of dedicated security auditing. The plugin needs to address the output escaping issue urgently to mitigate XSS risks.
Key Concerns
- 25 outputs, 0% properly escaped
- 1 flow with unsanitized paths
Kblog Metadata Security Vulnerabilities
Kblog Metadata Code Analysis
Output Escaping
Data Flow Analysis
Kblog Metadata Attack Surface
Shortcodes 3
WordPress Hooks 25
Maintenance & Trust
Kblog Metadata Maintenance & Trust
Maintenance Signals
Community Trust
Kblog Metadata Alternatives
Kblog Include
kblog-include
Transcludes content from arXiv and other academic repositories.
Scholar Publications Fetcher
scholar-publications-fetcher
A lightweight and high-performance plugin to fetch, cache, and display your Google Scholar publications in a clean, modern, and responsive card layout …
PubMed Posts
pubmed-posts
This plugin adds a dashboard widget that creates posts from PubMed articles, plus a search widget that finds posts with specific article data.
MathJax-LaTeX
mathjax-latex
This plugin enables MathJax (http://www.mathjax.org) functionality for WordPress (http://www.wordpress.org).
Zotpress
zotpress
Zotpress displays your Zotero citations on WordPress.
Kblog Metadata Developer Profile
2 plugins · 20 total installs
How We Detect Kblog Metadata
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kblog-metadata/kblog-metadata.php/wp-content/plugins/kblog-metadata/kblog-author.php/wp-content/plugins/kblog-metadata/kblog-table-of-contents.php/wp-content/plugins/kblog-metadata/kblog-headers.php/wp-content/plugins/kblog-metadata/kblog-title.php/wp-content/plugins/kblog-metadata/kblog-boilerplate.php/wp-content/plugins/kblog-metadata/kblog-transclude.php/wp-content/plugins/kblog-metadata/kblog-download.php+1 moreHTML / DOM Fingerprints
kblog-metadataname="kblog-metadata"id="kblog-metadata"[author]