Minitek Wall Security & Risk Analysis

wordpress.org/plugins/minitek-wall

A powerful masonry layout system for displaying content in WordPress.

30 active installs v1.2.1 PHP + WP 5.0+ Updated Jul 6, 2022
articles-displayarticles-gridarticles-wallposts-gridproducts-grid
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Minitek Wall Safe to Use in 2026?

Generally Safe

Score 85/100

Minitek Wall has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'minitek-wall' plugin v1.2.1 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and has no recorded vulnerabilities or CVEs, suggesting a history of secure development. However, significant concerns arise from its attack surface. With 5 total entry points, a concerning 4 of them lack authentication checks. This means that any user, regardless of their role or privileges, could potentially interact with these unprotected AJAX handlers, opening the door for various attacks.

While taint analysis showed no problematic flows and dangerous functions were absent, the lack of proper output escaping in 76% of outputs is a notable weakness. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled securely before being displayed to other users. The presence of only one nonce check and one capability check across the entire plugin further exacerbates the risk associated with the unprotected AJAX handlers, as these essential security mechanisms are not being consistently applied to protect sensitive actions.

In conclusion, the plugin's lack of historical vulnerabilities is a strong point, but the current version contains critical security flaws, particularly the high number of unprotected AJAX handlers and the extensive unescaped output. These issues create a substantial risk of unauthorized actions and XSS vulnerabilities, necessitating immediate attention and remediation.

Key Concerns

  • 4 unprotected AJAX handlers
  • 76% of outputs not properly escaped
  • Only 1 nonce check present
  • Only 1 capability check present
Vulnerabilities
None known

Minitek Wall Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Minitek Wall Release Timeline

v1.2.1Current
v1.2.0
v1.1.0
v1.0.4
v1.0.3
v1.0.2
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

Minitek Wall Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
378
118 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

24% escaped496 total outputs
Attack Surface
4 unprotected

Minitek Wall Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

authwp_ajax_wall_create_itemsincludes\class-minitek-wall.php:207
noprivwp_ajax_wall_create_itemsincludes\class-minitek-wall.php:208
authwp_ajax_wall_create_filtersincludes\class-minitek-wall.php:211
noprivwp_ajax_wall_create_filtersincludes\class-minitek-wall.php:212

Shortcodes 1

[mwall] public\class-minitek-wall-public.php:44
WordPress Hooks 17
actionadd_meta_boxesadmin\class-minitek-wall-admin-metaboxes.php:72
actionsave_postadmin\class-minitek-wall-admin-metaboxes.php:75
actionplugins_loadedincludes\class-minitek-wall.php:152
actionadmin_enqueue_scriptsincludes\class-minitek-wall.php:167
actionadmin_enqueue_scriptsincludes\class-minitek-wall.php:168
actioninitincludes\class-minitek-wall.php:171
actionadmin_menuincludes\class-minitek-wall.php:174
filtercustom_menu_orderincludes\class-minitek-wall.php:177
filtermanage_mwall_posts_columnsincludes\class-minitek-wall.php:180
actionmanage_mwall_posts_custom_columnincludes\class-minitek-wall.php:181
actionadmin_post_mwall_delete_cropped_imagesincludes\class-minitek-wall.php:184
actionadmin_noticesincludes\class-minitek-wall.php:187
actionwp_enqueue_scriptsincludes\class-minitek-wall.php:202
actionwp_enqueue_scriptsincludes\class-minitek-wall.php:203
actionadmin_enqueue_scriptsincludes\class-minitek-wall.php:225
actionload-post.phpincludes\class-minitek-wall.php:229
actionload-post-new.phpincludes\class-minitek-wall.php:230
Maintenance & Trust

Minitek Wall Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJul 6, 2022
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

Minitek Wall Developer Profile

Minitek.gr

2 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Minitek Wall

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/minitek-wall/admin/js/minitek-wall-admin-tabs.js
Version Parameters
minitek-wall/admin/js/minitek-wall-admin-tabs.js?ver=

HTML / DOM Fingerprints

CSS Classes
mwall
Data Attributes
data-post-typedata-category-filtering-typedata-categoriesdata-include-childrendata-tag-filtering-typedata-tags+116 more
FAQ

Frequently Asked Questions about Minitek Wall