mi13-glossary Security & Risk Analysis

wordpress.org/plugins/mi13-glossary

Glossary plugin for your site.

0 active installs v5 PHP + WP 4.7+ Updated Feb 10, 2026
glossarymodal-keys
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is mi13-glossary Safe to Use in 2026?

Generally Safe

Score 100/100

mi13-glossary has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The mi13-glossary v5 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, has no recorded vulnerability history, and avoids dangerous functions, file operations, and external HTTP requests. However, significant concerns arise from its attack surface, with three AJAX handlers identified, two of which lack authentication checks. This is a direct pathway for potential unauthorized actions if exploited. The taint analysis, while not revealing critical or high severity issues, did find one flow with unsanitized paths, which warrants attention as it could potentially lead to vulnerabilities if the input is not handled correctly downstream.

The absence of any recorded CVEs or past vulnerabilities is a strong positive indicator of the plugin's general security maturity. It suggests that the developers may be responsive to security concerns or that the plugin hasn't been a significant target. Nevertheless, the presence of unprotected AJAX endpoints and the unsanitized path flow are critical weaknesses that overshadow the otherwise positive aspects. A balanced conclusion would be that while the plugin benefits from a clean history and good SQL handling, its unprotected AJAX endpoints represent a tangible risk that needs immediate remediation.

Key Concerns

  • Unprotected AJAX handlers
  • Flows with unsanitized paths
Vulnerabilities
None known

mi13-glossary Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

mi13-glossary Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
14 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped17 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
mi13_glossary_modal_ajax (mi13-glossary.php:131)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

mi13-glossary Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 3

authwp_ajax_mi13_glossarymi13-glossary.php:127
noprivwp_ajax_mi13_glossarymi13-glossary.php:128
authwp_ajax_mi13_glossary_paginationmi13-glossary.php:601
WordPress Hooks 8
actioninitmi13-glossary.php:54
actionadmin_menumi13-glossary.php:87
actionload-post.phpmi13-glossary.php:89
actionwp_enqueue_scriptsmi13-glossary.php:124
filterthe_contentmi13-glossary.php:220
actionwp_trash_postmi13-glossary.php:629
actionsave_post_mi13_glossarymi13-glossary.php:630
actionpublish_mi13_glossarymi13-glossary.php:651
Maintenance & Trust

mi13-glossary Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 10, 2026
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

mi13-glossary Developer Profile

mi13

7 plugins · 20 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect mi13-glossary

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mi13-glossary/js/mi13_glossary_admin.js/wp-content/plugins/mi13-glossary/js/mi13_glossary.js/wp-content/plugins/mi13-glossary/css/mi13_glossary.css
Script Paths
/wp-content/plugins/mi13-glossary/js/mi13_glossary_admin.js/wp-content/plugins/mi13-glossary/js/mi13_glossary.js
Version Parameters
mi13_glossary_admin.js?ver=0.3mi13_glossary.js?ver=0.2mi13_glossary.css?ver=0.1

HTML / DOM Fingerprints

CSS Classes
mi13_glossary_linkmi13_glossary_contentmi13_glossary_closemi13_glossary_show
Data Attributes
data="maponclick="mi13_glossary()"
JS Globals
mi13_glossary_adminmi13_glossary_ajax
REST Endpoints
/wp-json/wp/v2/mi13_glossary
FAQ

Frequently Asked Questions about mi13-glossary