
Master PDF Viewer Security & Risk Analysis
wordpress.org/plugins/master-pdf-viewerMaster PDF Viewer
Is Master PDF Viewer Safe to Use in 2026?
Generally Safe
Score 85/100Master PDF Viewer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, "master-pdf-viewer" v0.1.0 exhibits a strong security posture with no identified vulnerabilities in its attack surface, code signals, or taint analysis. The absence of AJAX handlers, REST API routes, shortcodes, or cron events significantly limits potential entry points for malicious actors. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all outputs. The lack of file operations and external HTTP requests also reduces the plugin's attack surface.
The vulnerability history shows no recorded CVEs, which is a positive indicator. This lack of historical vulnerabilities, combined with the current clean static analysis, suggests that the plugin has been developed with security in mind or has not yet been a target for security researchers. However, it is important to note that the plugin is at a very early version (0.1.0), and the limited scope of the analysis (0 flows analyzed in taint analysis) might mean that more complex vulnerabilities could exist but were not detected by this specific analysis. The complete absence of nonce checks and capability checks across all potential entry points (though there are none in this case) is a potential area for concern should the plugin's attack surface expand in future versions.
In conclusion, "master-pdf-viewer" v0.1.0 appears to be secure at this early stage of development, with excellent adherence to secure coding practices within the analyzed code. The lack of any identified vulnerabilities is a significant strength. The primary weakness lies in the potential for future vulnerabilities to emerge as the plugin develops, particularly concerning the absence of checks that would become critical with a larger attack surface.
Master PDF Viewer Security Vulnerabilities
Master PDF Viewer Code Analysis
Output Escaping
Master PDF Viewer Attack Surface
WordPress Hooks 4
Maintenance & Trust
Master PDF Viewer Maintenance & Trust
Maintenance Signals
Community Trust
Master PDF Viewer Alternatives
Classic Editor
classic-editor
Enables the previous "classic" editor and the old-style Edit Post screen with TinyMCE, Meta Boxes, etc. Supports all plugins that extend this screen.
Starter Templates – AI-Powered Templates for Elementor & Gutenberg
astra-sites
The growing library of 300+ ready-to-use templates that work with all WordPress themes including Astra, Hello, OceanWP, GeneratePress and more
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Spectra Gutenberg Blocks – Website Builder for the Block Editor
ultimate-addons-for-gutenberg
Power-up Gutenberg with advanced blocks for faster website creation. Build your WordPress website effortlessly using powerful building blocks!
Breadcrumb NavXT
breadcrumb-navxt
Adds breadcrumb navigation showing the visitor's path to their current location.
Master PDF Viewer Developer Profile
2 plugins · 20 total installs
How We Detect Master PDF Viewer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/master-pdf-viewer/build/wp-content/plugins/master-pdf-viewer/pdf-js/build/pdf.worker.js/wp-content/plugins/master-pdf-viewer/pdf-js/build/pdf.jsmaster-pdf-viewerHTML / DOM Fingerprints
mpv_pdf_wrapperpdf_iframeallowsandboxtitlewidthheightclass<div class="mpv_pdf_wrapper<iframe allow="accelerometer; ambient-light-sensor; camera; encrypted-media; geolocation; gyroscope; hid; microphone; midi; payment; usb; vr; xr-spatial-tracking" sandbox="allow-forms allow-modals allow-popups allow-presentation allow-same-origin allow-scripts allow-downloads allow-pointer-lock" src="