Klout score Widget Security & Risk Analysis

wordpress.org/plugins/klout-score-badge-with-klout-api-v2

This plugin allows you to display your Klout score in a elegant way using the Klout API V2.

10 active installs v1.4 PHP + WP 3.0.1+ Updated Jul 8, 2014
badgeklout
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Klout score Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Klout score Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

This plugin, "klout-score-badge-with-klout-api-v2" version 1.4, exhibits a mixed security posture. On the positive side, the static analysis shows no identified dangerous functions, no raw SQL queries, and no external HTTP requests, which are common vectors for exploitation. The absence of known CVEs in its history further suggests a generally stable past. However, a significant concern is the complete lack of proper output escaping, with 0% of its 28 identified outputs being correctly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if any user-controlled data is ever rendered without sanitization. Additionally, the absence of nonce checks and capability checks on any of its potential entry points is worrying, especially if any new entry points are introduced in future updates or if the reported count of 0 entry points is inaccurate due to analysis limitations. The file operations are also a point of attention, although the nature and context of these operations are not detailed, they could pose a risk if not handled securely.

Key Concerns

  • Output escaping is not implemented
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Klout score Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Klout score Widget Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Klout score Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped28 total outputs
Attack Surface

Klout score Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initkscore.php:10
Maintenance & Trust

Klout score Widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJul 8, 2014
PHP min version
Downloads3K

Community Trust

Rating84/100
Number of ratings5
Active installs10
Developer Profile

Klout score Widget Developer Profile

ghostichou

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Klout score Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/klout-score-badge-with-klout-api-v2/img/klout-logo.png

HTML / DOM Fingerprints

CSS Classes
kscore-widget
Data Attributes
data-href="http://matthieufleitz.fr/site/article/afficher-score-Klout-dans-wordpress"data-send="false"data-layout="box_count"data-width="450"data-show-faces="true"data-action="recommend"
JS Globals
FB
FAQ

Frequently Asked Questions about Klout score Widget