
kk blog card Security & Risk Analysis
wordpress.org/plugins/kk-blog-cardショートコードを利用してブログカードを表示するプラグイン
Is kk blog card Safe to Use in 2026?
Generally Safe
Score 85/100kk blog card has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The kk-blog-card plugin v1.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices in areas such as using prepared statements for all SQL queries and ensuring all output is properly escaped. There are no known CVEs associated with this plugin, suggesting a generally stable history. However, the static analysis reveals significant concerns, particularly regarding its attack surface. The presence of an unprotected REST API route is a notable weakness, as it represents a direct entry point that could be exploited without proper authorization checks. The absence of nonce checks on its AJAX handlers, although there are none, is also a potential area for future vulnerabilities if AJAX functionality is added without adequate security. The plugin also performs file operations and makes external HTTP requests, which, while not inherently insecure, can become vectors for attack if not handled with extreme care and proper validation.
Key Concerns
- Unprotected REST API route
- Zero nonce checks on AJAX handlers
- File operations without clear context
- External HTTP requests without clear context
kk blog card Security Vulnerabilities
kk blog card Code Analysis
SQL Query Safety
kk blog card Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
kk blog card Maintenance & Trust
Maintenance Signals
Community Trust
kk blog card Alternatives
Pz-LinkCard
pz-linkcard
This plugin is intended to display a link in a blog card format. The goodbye to the text-only link.
Simple Blog Card
simple-blog-card
Get OGP and display blog card.
Pz-HatenaBlogCard
pz-hatenablogcard
This plug-in to display a link in the article by using the "Hatena blog card".
SU Blocks Blogcard
blogcard-for-wp
A WordPress plugin that makes it easy to create blog cards. Simply enter a URL and automatically fetch metadata to display beautiful cards.
WWI Blogcard
wwi-blogcard
A WordPress block plugin that generates beautiful blog cards from URLs using OGP information.
kk blog card Developer Profile
1 plugin · 30 total installs
How We Detect kk blog card
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kk-blog-card/index.jskk-blog-card/index.js?ver=1.3HTML / DOM Fingerprints
data-type/wp-json/v1/kkblogcard<blog-card href=data-type=