
Mi librería Security & Risk Analysis
wordpress.org/plugins/mi-libreriaMi librería te permite añadir automáticamente a los artículos de tu blog una selección de los mejores libros sobre el tema de tu artículo
Is Mi librería Safe to Use in 2026?
Generally Safe
Score 85/100Mi librería has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mi-libreria" v1.3 plugin exhibits several concerning security weaknesses despite its clean vulnerability history. A significant portion of its attack surface, specifically 5 out of 6 entry points, lacks authentication checks. This means that any user, including unauthenticated ones, could potentially interact with these unprotected AJAX handlers. Furthermore, the code analysis revealed a critical vulnerability in the use of the `create_function` PHP function, which is known to be insecure and can lead to arbitrary code execution if user input is passed to it without proper sanitization. While SQL queries are properly prepared and there are no identified critical or high severity taint flows, the lack of output escaping on a substantial percentage of outputs (68%) indicates a risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks on AJAX handlers is another critical oversight that exposes the plugin to CSRF attacks.
Despite the lack of recorded CVEs, which is a positive sign, it does not negate the immediate risks identified in the static analysis. The plugin's current state suggests a general lack of robust security implementation. The presence of dangerous functions, unprotected entry points, and insufficient output escaping creates a fertile ground for exploitation. While the SQL query handling is commendable, it is overshadowed by other critical vulnerabilities. The plugin requires immediate attention to address the identified security flaws to mitigate potential risks to WordPress sites.
In conclusion, "mi-libreria" v1.3 has a weak security posture due to numerous unprotected entry points and the use of a dangerous function. The lack of output escaping and nonce checks further exacerbates these risks, making it vulnerable to XSS and CSRF attacks. While the absence of recorded vulnerabilities is a positive, it is overshadowed by the critical issues found in the static analysis. Immediate remediation is strongly recommended.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function: create_function
- Output escaping: 68% not properly escaped
- Nonce checks: 0
- Capability checks: 1 (likely insufficient)
- Unsanitized paths in taint flows
Mi librería Security Vulnerabilities
Mi librería Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Mi librería Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Mi librería Maintenance & Trust
Maintenance Signals
Community Trust
Mi librería Alternatives
Holnix
holnix
Holnix permite a las librerías importar catálogos editoriales (metadata ONIX) directamente a WooCommerce.
Lenix Leads Collector
lenix-elementor-leads-addon
Leads Collector, Collects forms entries from Elementor,Cf7,WPForms and more with export to CSV.
Plugins Garbage Collector (Database Cleanup)
plugins-garbage-collector
Find unused database tables from deactivated or deleted plugins. You can delete unused database tables to reduce database volume and enhance site perf …
WPML Widgets
wpml-widgets
WPML Widgets is a simple to use extension to add a language selector dropdown to your widgets.
Libro de Reclamaciones y Quejas
libro-de-reclamaciones-y-quejas
Libro de reclamaciones válido para Perú con los campos obligatorios exigidos por Indecopi.
Mi librería Developer Profile
3 plugins · 380 total installs
How We Detect Mi librería
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mi-libreria/css/prh-ml-metabox.css/wp-content/plugins/mi-libreria/js/prh-ml-metabox.js/wp-content/plugins/mi-libreria/css/prh-ml-options.css/wp-content/plugins/mi-libreria/js/prh-ml-options.js/wp-content/plugins/mi-libreria/css/prh-ml-front.css/wp-content/plugins/mi-libreria/js/prh-ml-front.js/wp-content/plugins/mi-libreria/js/prh-ml-metabox.js/wp-content/plugins/mi-libreria/js/prh-ml-options.js/wp-content/plugins/mi-libreria/js/prh-ml-front.jsHTML / DOM Fingerprints
prh_ml_containerprh_ml_bookprh_ml_book_containerprh_ml_coverprh_ml_titledata-pidprh_ml_ajaxwp-admin/admin-ajax.php<div data-pid="