
My Envato Security & Risk Analysis
wordpress.org/plugins/my-envatoA super simple plugin to display your recent 25 items from an Envato Marketplace.
Is My Envato Safe to Use in 2026?
Generally Safe
Score 85/100My Envato has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "my-envato" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has a history free of known vulnerabilities. The attack surface is also minimal, with only one shortcode identified and no unprotected entry points found in the static analysis.
However, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a notable risk, as it can be exploited for code injection if not handled with extreme care and sanitization. More critically, a staggering 100% of output is not properly escaped. This creates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website's content, potentially leading to session hijacking, defacement, or further compromise.
Given the lack of documented vulnerabilities, it's difficult to ascertain past security issues. However, the current analysis highlights potential weaknesses that could lead to future exploits. The plugin has strengths in its SQL handling and attack surface management but falls short on output sanitization, which is a fundamental security requirement. The use of `create_function` also warrants immediate attention. Overall, while not riddled with critical flaws, the unescaped output and use of `create_function` present substantial risks that need to be addressed.
Key Concerns
- Output escaping missing on 100% of outputs
- Use of dangerous function create_function
- No nonce checks implemented
- No capability checks implemented
My Envato Security Vulnerabilities
My Envato Code Analysis
Dangerous Functions Found
Output Escaping
My Envato Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
My Envato Maintenance & Trust
Maintenance Signals
Community Trust
My Envato Alternatives
Envato Marketplace Widget
envato-marketplace-widget
Widget to display recent or popular items from the Envato marketplace.
Meks ThemeForest Smart Widget
meks-themeforest-smart-widget
Easily display ThemeForest items inside WordPress widget.
GS Portfolio for Envato
gs-envato-portfolio
Best Responsive Envato Portfolio Plugin to display Themeforest & Codecanyon Items.
Preview Link Generator
preview-link-generator
Preview Link Generator is a plugin to help you create demo/preview links for your WordPress themes, plugins, HTML templates preview.
Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy
dokan-lite
Transform your WooCommerce site into a multivendor marketplace with Dokan – an AI powered & advanced WooCommerce marketplace solution
My Envato Developer Profile
4 plugins · 5K total installs
How We Detect My Envato
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
my-envato-item-anchor-classmy-envato-item-image-classdata-marketplacedata-user<li style="padding: 0 10px 10px 0; float:left;"><a href="" title="View " class="