
mowsterGlossary Security & Risk Analysis
wordpress.org/plugins/mowster-glossaryAllows to manage and display a glossary in WordPress.
Is mowsterGlossary Safe to Use in 2026?
Generally Safe
Score 85/100mowsterGlossary has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mowster-glossary" v2.4.2 plugin presents a mixed security posture. While it has no recorded vulnerabilities or known CVEs, indicating a history of relative security, the static analysis reveals significant concerns that could lead to future issues. The plugin has a single AJAX entry point that lacks any authentication checks, creating a direct avenue for unauthorized actions. Furthermore, a high percentage of identified code flows (11 out of 12) contain unsanitized paths, with 5 deemed to be of high severity. This suggests a substantial risk of injection vulnerabilities, particularly given the absence of proper output escaping for any of the identified outputs.
While the plugin uses prepared statements for a majority of its SQL queries, the lack of output escaping is a critical weakness that could expose users to cross-site scripting (XSS) attacks. The absence of nonce checks on the unprotected AJAX handler further compounds this risk. Although there are no direct critical severity taint flows reported, the high number of high-severity flows with unsanitized paths, combined with the unprotected AJAX endpoint and complete lack of output escaping, presents a notable attack surface that requires immediate attention to prevent potential exploits.
Key Concerns
- Unprotected AJAX handler
- High number of unsanitized paths (high severity)
- No output escaping
- Missing nonce checks
mowsterGlossary Security Vulnerabilities
mowsterGlossary Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
mowsterGlossary Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
mowsterGlossary Maintenance & Trust
Maintenance Signals
Community Trust
mowsterGlossary Alternatives
Heroic Glossary – Block for building Glossaries, Dictionaries and more
heroic-glossary
The best WordPress glossary builder plugin to create and manage your own glossary of terms.
LuckyWP Glossary
luckywp-glossary
The plugin implements the glossary/dictionary functionality with support of synonyms.
iThoughts Tooltip Glossary
ithoughts-tooltip-glossary
Create beautiful tooltips for descriptions or glossary terms, easily
Glossary
automatic-glossary
Given a collection of glossary definition pages, automatically creates links in your page and post content for the words in your glossary.
Easy Glossary
easy-glossary
A lightweight, flexible glossary plugin that auto-links terms, shows tooltips, and provides an index shortcode.
mowsterGlossary Developer Profile
2 plugins · 20 total installs
How We Detect mowsterGlossary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mowster-glossary/styles/glossary.css/wp-content/plugins/mowster-glossary/js/add.js/wp-content/plugins/mowster-glossary/js/edit.js/wp-content/plugins/mowster-glossary/js/list.js/wp-content/plugins/mowster-glossary/js/options.js/wp-content/plugins/mowster-glossary/js/add.js/wp-content/plugins/mowster-glossary/js/edit.js/wp-content/plugins/mowster-glossary/js/list.js/wp-content/plugins/mowster-glossary/js/options.jsmowster-glossary/styles/glossary.css?ver=mowster-glossary/js/add.js?ver=mowster-glossary/js/edit.js?ver=mowster-glossary/js/list.js?ver=mowster-glossary/js/options.js?ver=HTML / DOM Fingerprints
mowsterGmowsterG_term_defaultmowsterG_term_lenght_errormowsterG_definition_errormowsterG_admin_urlmowsterG_terms_per_page_warningmowsterG_terms+7 moremowsterGmowsterG_listmowsterG_options