
Mimo Masonry Security & Risk Analysis
wordpress.org/plugins/mimo-masonryCreates a Widget to display a Masonry, Infinite scroll, filterable loop of posts or whatever custom post type you have. Includes 1-20 columns layout.
Is Mimo Masonry Safe to Use in 2026?
Generally Safe
Score 85/100Mimo Masonry has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mimo-masonry v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent security practices regarding its attack surface, with zero exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or permission checks. Furthermore, all SQL queries are correctly implemented using prepared statements, and there are no file operations or external HTTP requests, minimizing common attack vectors. The absence of known vulnerabilities in its history is also a strong indicator of a well-maintained and secure plugin.
However, the static analysis reveals significant concerns within the code itself. The presence of the `create_function` is a critical security risk, as it can be exploited for arbitrary code execution if its arguments are not strictly controlled. Additionally, a substantial portion of output is not properly escaped (38% properly escaped means 62% is unescaped), opening the door to cross-site scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks on its entry points, although currently a null set, implies that if any entry points were to be introduced in the future, they would likely be unprotected.
In conclusion, while the plugin's current attack surface is commendably small and its historical security record is clean, the identified code-level issues, particularly `create_function` and unescaped output, present tangible risks. These require immediate attention to prevent potential exploits. The lack of fundamental security checks like nonces and capability checks suggests a potential blind spot in secure development practices for any future expansion of the plugin's functionality.
Key Concerns
- Use of create_function (potential RCE)
- Insufficient output escaping (XSS risk)
- Missing nonce checks
- Missing capability checks
Mimo Masonry Security Vulnerabilities
Mimo Masonry Code Analysis
Dangerous Functions Found
Output Escaping
Mimo Masonry Attack Surface
WordPress Hooks 9
Maintenance & Trust
Mimo Masonry Maintenance & Trust
Maintenance Signals
Community Trust
Mimo Masonry Alternatives
Wp Loop
wp-loop
Creates a Widget to display a Masonry, Infinite scroll, filterable loop of posts or whatever custom post type you have. Includes 1-20 columns layout.
Query Loop Masonry Lite
ph-queryloop-masonry-lite
Add beautiful masonry layouts to WordPress Query Loop blocks. Pinterest-style grids with no vendor lock-in.
Post Grid
post-grid
Post Grid is a powerful WordPress plugin for creating customizable post grid layouts with advanced query options, allowing users to display posts dyna …
Lightweight Grid Columns
lightweight-grid-columns
Easily add desktop, tablet and mobile friendly columns to your content using an easy to use shortcode.
JetGridBuilder — Grid Builder for Elementor and Gutenberg
jetgridbuilder
JetGridBuilder plugin for Elementor and Gutenberg free addon for creating wow-grids on your website. Forget about the limits of premade layouts.
Mimo Masonry Developer Profile
8 plugins · 910 total installs
How We Detect Mimo Masonry
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mimo-masonry/css/widget.css/wp-content/plugins/mimo-masonry/js/widget.js/wp-content/plugins/mimo-masonry/js/widget.jsmimo-masonry/css/widget.css?ver=mimo-masonry/js/widget.js?ver=HTML / DOM Fingerprints
mimo_masonry-classdata-columnsdata-imagesizedata-posttypedata-offsetdata-showpostsdata-filter+30 moremimo_masonry_widget_id