Memorable Password Security & Risk Analysis

wordpress.org/plugins/memorable-password

This plugin generates a memorable and strong password. For example, animals, country names, foods etc.

10 active installs v1.0.1 PHP + WP 4.3+ Updated Apr 23, 2020
password
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Memorable Password Safe to Use in 2026?

Generally Safe

Score 85/100

Memorable Password has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "memorable-password" plugin v1.0.1 exhibits a seemingly good security posture based on the provided static analysis, with no identified attack surface, dangerous functions, or SQL queries outside of prepared statements. The absence of file operations, external HTTP requests, and vulnerability history further suggests a low immediate risk. However, a significant concern arises from the complete lack of output escaping (0% properly escaped). This means any dynamic data displayed by the plugin is not being sanitized, leaving it vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce and capability checks, while not directly exploitable due to the zero attack surface, indicates a potential lack of robust security practices that could become problematic if the plugin's functionality were to expand or change in the future. The plugin's current limited scope mitigates the immediate impact of these weaknesses, but the unescaped output represents a tangible, exploitable flaw.

Key Concerns

  • Output escaping is not implemented
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Memorable Password Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Memorable Password Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

Memorable Password Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedmemorable-password.php:61
actionadmin_menumemorable-password.php:81
actionadmin_initmemorable-password.php:82
filterrandom_passwordmemorable-password.php:83
Maintenance & Trust

Memorable Password Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 23, 2020
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Memorable Password Developer Profile

Ko Takagi

5 plugins · 2K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
330 days
View full developer profile
Detection Fingerprints

How We Detect Memorable Password

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Memorable Password