Knowledge Base – Knowledge Base Maker Security & Risk Analysis

wordpress.org/plugins/knowledge-base-maker

Organize your documentation and FAQs with our Knowledge Base Maker plugin. It's easy to use, flexible and professional.

200 active installs v1.1.8 PHP + WP 3.8+ Updated Jan 26, 2023
pollpoll-formpolls
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJun 19, 2025
Download
Safety Verdict

Is Knowledge Base – Knowledge Base Maker Safe to Use in 2026?

Use With Caution

Score 63/100

Knowledge Base – Knowledge Base Maker has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jun 19, 2025Updated 3yr ago
Risk Assessment

The 'knowledge-base-maker' plugin v1.1.8 exhibits a generally good security posture with strong adherence to secure coding practices. The static analysis reveals a relatively small attack surface with no unprotected entry points. The plugin demonstrates a high percentage of properly escaped outputs and a good number of nonce and capability checks. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is commendable. The taint analysis also shows no critical or high severity unsanitized flows, indicating a low risk of direct code injection or sensitive data exposure through untrusted input.

However, a significant concern arises from the plugin's vulnerability history. The presence of one unpatched medium severity CVE, specifically a Cross-Site Request Forgery (CSRF) vulnerability, indicates a past weakness that has not yet been addressed. The recurrence of CSRF as a common vulnerability type is a pattern that warrants attention, suggesting a potential recurring oversight in handling user actions. While the current code analysis doesn't expose this specific CSRF vulnerability, the historical data suggests a latent risk that could be re-introduced or remain exploitable if not addressed.

In conclusion, 'knowledge-base-maker' v1.1.8 scores well on proactive security measures like input validation and output escaping. The static analysis paints a picture of a well-built plugin. The primary weakness lies in its unpatched historical vulnerability, which significantly impacts its overall trustworthiness. Addressing the outstanding CVE should be a priority to mitigate the risk associated with past security flaws.

Key Concerns

  • Unpatched CVE (medium severity)
  • SQL queries not fully prepared
  • Minor unescaped output
Vulnerabilities
1 published

Knowledge Base – Knowledge Base Maker Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-52791medium · 4.3Cross-Site Request Forgery (CSRF)

Knowledge Base &#8211; Knowledge Base Maker <= 1.1.8 - Cross-Site Request Forgery

Jun 19, 2025Unpatched
Version History

Knowledge Base – Knowledge Base Maker Release Timeline

v1.1.8Current1 CVE
v1.1.7.11 CVE
v1.1.71 CVE
v1.1.61 CVE
v1.1.51 CVE
v1.1.41 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.91 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Knowledge Base – Knowledge Base Maker Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
1 prepared
Unescaped Output
2
30 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared2 total queries

Output Escaping

94% escaped32 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
search (com\classes\global\Ajax.php:14)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Knowledge Base – Knowledge Base Maker Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_ykb_search_datacom\classes\global\Ajax.php:10
authwp_ajax_ykb_search_datacom\classes\global\Ajax.php:11

Shortcodes 1

[ykb_knowledge_base] com\classes\global\Actions.php:11
WordPress Hooks 9
actionadmin_headcom\classes\admin\Actions.php:11
actionadd_meta_boxescom\classes\admin\Actions.php:12
actionadmin_post_ykb_save_configurationcom\classes\admin\Actions.php:14
actionadmin_action_ykb_duplicate_post_as_draftcom\classes\admin\Actions.php:15
actionadmin_enqueue_scriptscom\classes\admin\CSS.php:12
filterpost_row_actionscom\classes\admin\Filters.php:11
actioninitcom\classes\global\Actions.php:10
actionadmin_menucom\classes\global\Actions.php:12
actionadmin_initcom\classes\YkbInit.php:16
Maintenance & Trust

Knowledge Base – Knowledge Base Maker Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedJan 26, 2023
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

Knowledge Base – Knowledge Base Maker Developer Profile

devfelixmoira

6 plugins · 2K total installs

80
trust score
Avg Security Score
80/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Knowledge Base – Knowledge Base Maker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/knowledge-base-maker/com/views/searchBar.php/wp-content/plugins/knowledge-base-maker/assets/css/knowledgeBase.css/wp-content/plugins/knowledge-base-maker/assets/js/searchBar.js
Script Paths
/wp-content/plugins/knowledge-base-maker/assets/js/searchBar.js
Version Parameters
knowledge-base-maker/assets/css/knowledgeBase.css?ver=knowledge-base-maker/assets/js/searchBar.js?ver=

HTML / DOM Fingerprints

Data Attributes
ykb-post-id
JS Globals
YKB_ARGS
Shortcode Output
<!-- Search Bar -->
FAQ

Frequently Asked Questions about Knowledge Base – Knowledge Base Maker