KdTips Google Plus badge Security & Risk Analysis

wordpress.org/plugins/kd-google-plus-badge

Anyone tell you that it is very easy to add Google Plus Badge to your wordpress Blog or website damm easy with KD Google Plus Badge plugin.

10 active installs v1.2 PHP + WP 3.0+ Updated Sep 5, 2013
badgegooglegoogle-plusgoogle-plus-pagespages
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is KdTips Google Plus badge Safe to Use in 2026?

Generally Safe

Score 85/100

KdTips Google Plus badge has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "kd-google-plus-badge" v1.2 plugin exhibits a mixed security posture. While the plugin demonstrates good practices by not making external HTTP requests and using prepared statements for all SQL queries, significant concerns arise from the static code analysis. The presence of the dangerous `create_function` is a clear red flag, as it can be exploited for remote code execution under certain circumstances. Furthermore, the complete lack of output escaping for all 43 identified outputs is highly problematic, creating a strong risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on the single entry point (the shortcode) also means that the shortcode's functionality could be triggered by unauthenticated or unauthorized users, potentially leading to unintended actions or information disclosure depending on what the shortcode does.

Key Concerns

  • Dangerous function used (create_function)
  • 100% of outputs are unescaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

KdTips Google Plus badge Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

KdTips Google Plus badge Release Timeline

v1.2Current
v1.1
Code Analysis
Analyzed Mar 16, 2026

KdTips Google Plus badge Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
43
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'register_widget("kd_google_plus_badge");'));kd_google_plus_badge.php:26

Output Escaping

0% escaped43 total outputs
Attack Surface

KdTips Google Plus badge Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[kd_google_badge] kd_google_plus_badge.php:375
WordPress Hooks 3
actionwidgets_initkd_google_plus_badge.php:26
actionwp_footerkd_google_plus_badge.php:97
actionadmin_menukd_google_plus_badge.php:374
Maintenance & Trust

KdTips Google Plus badge Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedSep 5, 2013
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

KdTips Google Plus badge Developer Profile

Purvesh

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect KdTips Google Plus badge

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://apis.google.com/js/plusone.js

HTML / DOM Fingerprints

CSS Classes
g-communityg-pageg-person
Data Attributes
data-themedata-widthdata-hrefdata-layoutdata-showcoverphotodata-showtagline+1 more
FAQ

Frequently Asked Questions about KdTips Google Plus badge