
KCite Security & Risk Analysis
wordpress.org/plugins/kciteA tool for producing citations and bibliographies in Wordpress posts. Developed for the Knowledgeblog project (http://knowledgeblog.org).
Is KCite Safe to Use in 2026?
Generally Safe
Score 85/100KCite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The kcite plugin version 1.6.3 presents a generally positive security posture based on the static analysis. The plugin demonstrates good practices by not exposing any AJAX handlers or REST API routes without proper authentication and authorization checks, which significantly limits its attack surface. Furthermore, all SQL queries utilize prepared statements, indicating a strong defense against SQL injection vulnerabilities. The absence of file operations and dangerous functions is also a positive sign. However, there are areas for improvement. The low percentage of properly escaped output (20%) is a significant concern, as it exposes the plugin to potential Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. While no critical or high severity taint flows were detected, one flow with an unsanitized path suggests a potential for indirect path traversal vulnerabilities, which warrants further investigation. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a track record of secure development or infrequent targeting, but this cannot be solely relied upon for long-term security. The overall security is good due to the lack of common critical vulnerabilities, but the output escaping and unsanitized path flow are notable weaknesses that could be exploited.
Key Concerns
- Low output escaping percentage
- Unsanitized path flow detected
KCite Security Vulnerabilities
KCite Code Analysis
Output Escaping
Data Flow Analysis
KCite Attack Surface
Shortcodes 2
WordPress Hooks 7
Maintenance & Trust
KCite Maintenance & Trust
Maintenance Signals
Community Trust
KCite Alternatives
Citation Importer
citation-importer
Import a citation or bibliography as posts.
CiteKit – Citation and Reference Manager
citation-reference-manager
Add in-text citations, tooltips, and auto-generated bibliography to your WordPress posts in APA, MLA, Chicago and more.
WebKew WP References and Citations
webkew-wp-references-and-citations
A WordPress plugin that automatically generates a bibliography from citations added to a WP post/page/custom post type.
Modern Footnotes
modern-footnotes
Add inline footnotes to your posts. On desktop, the footnotes will appear as tooltips. On mobile, the footnote will expand beneath the text.
Resizable Sidebar for the Gutenberg Block Editor
resizable-editor-sidebar
An intuitive solution to make the default WordPress Gutenberg sidebar resizable.
KCite Developer Profile
2 plugins · 10K total installs
How We Detect KCite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kcite-citeproc/xmldom.js/wp-content/plugins/kcite-citeproc/citeproc.js/wp-content/plugins/kcite-citeproc/kcite_locale_style.js/wp-content/plugins/kcite-citeproc/kcite.js/wp-content/plugins/kcite-citeproc/xmldom.js/wp-content/plugins/kcite-citeproc/citeproc.js/wp-content/plugins/kcite-citeproc/kcite_locale_style.js/wp-content/plugins/kcite-citeproc/kcite.jsHTML / DOM Fingerprints
kcite-section<!-- Kcite Plugin Installed--><!-- kcite-sectionkcite-section-idwindow.kcitewindow.kcite_locale_style/wp-json/kcite-<div class="kcite-section"