Men Quotes On Women Security & Risk Analysis

wordpress.org/plugins/men-quotes-on-women

Adds a sidebar widget that displays randomly men's quotes about women and "being woman".

10 active installs v2.0.1 PHP + WP 2.5+ Updated Feb 9, 2014
manmenquotequotessidebar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Men Quotes On Women Safe to Use in 2026?

Generally Safe

Score 85/100

Men Quotes On Women has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The "men-quotes-on-women" plugin v2.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no recorded vulnerabilities (CVEs). The attack surface is minimal, with only one shortcode and no external HTTP requests or file operations, which reduces potential entry points for attackers. However, significant concerns arise from the static code analysis. The presence of the `create_function` dangerous function is a red flag, as it can lead to code injection vulnerabilities if not handled with extreme care. More critically, none of the outputs are properly escaped, making the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. The complete absence of nonce checks and capability checks on its single entry point (the shortcode) further exacerbates this risk, as it allows any user to trigger the shortcode's functionality without proper authorization or validation, potentially leading to unintended actions or data exposure. The lack of taint analysis results is neutral but doesn't negate the identified code-level risks.

Key Concerns

  • Dangerous function create_function used
  • Outputs not properly escaped (XSS risk)
  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Men Quotes On Women Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Men Quotes On Women Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("WP_Widget_Men_Quotes_On_Womemen-quotes-on-women.php:135

Output Escaping

0% escaped7 total outputs
Attack Surface

Men Quotes On Women Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[men-quotes-on-women] men-quotes-on-women.php:134
WordPress Hooks 1
actionwidgets_initmen-quotes-on-women.php:135
Maintenance & Trust

Men Quotes On Women Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedFeb 9, 2014
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Men Quotes On Women Developer Profile

philippe

9 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Men Quotes On Women

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
Men Quotes On Women widget plugin for WordPress
Shortcode Output
<table width="250" style="border-width: thin thin thin thin; border-style: solid solid solid solid;"><thead><tr><th><center><font face="arial" size="+1"><b>Men Quotes On Women</b></center></font></th></tr></thead><tbody><tr><td><div style="text-align: justify;"></div><div style="text-align: right;">
FAQ

Frequently Asked Questions about Men Quotes On Women