Leira Letter Avatar Security & Risk Analysis

wordpress.org/plugins/leira-letter-avatar

Automatically generate beautiful user avatars based on their initials.

6K active installs v1.3.13 PHP 8.0+ WP 4.7+ Updated Dec 18, 2025
avatarimageinitialletteruser
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Leira Letter Avatar Safe to Use in 2026?

Generally Safe

Score 100/100

Leira Letter Avatar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The leira-letter-avatar plugin version 1.3.13 exhibits a generally strong security posture, particularly in its handling of SQL queries and output escaping, with 100% of both being properly managed. The absence of known vulnerabilities in its history further suggests a diligent development approach. However, a significant concern arises from the plugin's attack surface. It possesses one unprotected AJAX handler, which represents a direct entry point for unauthenticated users. While there are no identified critical taint flows or dangerous functions, this single unprotected AJAX handler presents a potential risk for unauthorized actions or information disclosure if exploited. The presence of a nonce check and capability checks in the code is positive, but these are insufficient if the primary entry point lacks proper authentication or authorization. The plugin's strength lies in its robust internal code practices, but its weakness lies in an exposed, unauthenticated interaction point.

Key Concerns

  • Unprotected AJAX handler identified
Vulnerabilities
None known

Leira Letter Avatar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Leira Letter Avatar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
24 escaped
Nonce Checks
1
Capability Checks
4
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped24 total outputs
Attack Surface
1 unprotected

Leira Letter Avatar Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_leira_letter_avatar_footer_ratedincludes\class-leira-letter-avatar.php:211
WordPress Hooks 16
actionplugins_loadedincludes\class-leira-letter-avatar.php:177
filteravatar_defaultsincludes\class-leira-letter-avatar.php:197
actionadmin_menuincludes\class-leira-letter-avatar.php:199
actionadmin_initincludes\class-leira-letter-avatar.php:201
filterplugin_action_linksincludes\class-leira-letter-avatar.php:203
actionadmin_enqueue_scriptsincludes\class-leira-letter-avatar.php:205
filteradmin_body_classincludes\class-leira-letter-avatar.php:207
filteradmin_footer_textincludes\class-leira-letter-avatar.php:209
filterget_avatar_urlincludes\class-leira-letter-avatar.php:230
actionwp_enqueue_scriptsincludes\class-leira-letter-avatar.php:232
filterbp_core_fetch_avatar_no_gravincludes\class-leira-letter-avatar.php:242
filterbp_core_avatar_defaultincludes\class-leira-letter-avatar.php:248
filterbp_core_default_avatarincludes\class-leira-letter-avatar.php:250
filterbb_attachments_get_default_profile_group_avatar_imageincludes\class-leira-letter-avatar.php:254
filterum_user_avatar_url_filterincludes\class-leira-letter-avatar.php:256
filterget_avatar_urlincludes\class-leira-letter-avatar.php:258
Maintenance & Trust

Leira Letter Avatar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 18, 2025
PHP min version8.0
Downloads29K

Community Trust

Rating98/100
Number of ratings27
Active installs6K
Developer Profile

Leira Letter Avatar Developer Profile

Ariel

3 plugins · 9K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
12 days
View full developer profile
Detection Fingerprints

How We Detect Leira Letter Avatar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leira-letter-avatar/build/admin.js/wp-content/plugins/leira-letter-avatar/build/admin.css
Script Paths
/wp-content/plugins/leira-letter-avatar/build/admin.js
Version Parameters
leira-letter-avatar/build/admin.js?ver=leira-letter-avatar/build/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
leira_letter_avatarleira_letter_avatar_rounded
Data Attributes
data-nonce-action="leira-letter-avatar"
JS Globals
window.leira_letter_avatar
FAQ

Frequently Asked Questions about Leira Letter Avatar