My Faves for WP Security & Risk Analysis

wordpress.org/plugins/my-faves

Save your favorite posts, add tags, and list them.

10 active installs v1.2.5 PHP 7.0+ WP 4.9.0+ Updated Aug 4, 2022
bookmarkfavorite
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is My Faves for WP Safe to Use in 2026?

Generally Safe

Score 85/100

My Faves for WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "my-faves" plugin version 1.2.5 exhibits a generally good security posture, with no reported vulnerabilities and a notable absence of dangerous functions or raw SQL queries. The code analysis indicates a strong reliance on prepared statements for SQL, which is a significant strength. However, a concern arises from the output escaping, where only 45% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being rendered in the browser.

Key Concerns

  • Low output escaping coverage
Vulnerabilities
None known

My Faves for WP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

My Faves for WP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
13 escaped
Nonce Checks
4
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

45% escaped29 total outputs
Attack Surface

My Faves for WP Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 3

authwp_ajax_myfavesaddincludes\service.php:5
authwp_ajax_myfavesremoveincludes\service.php:29
authwp_ajax_myfavesaddtagsincludes\service.php:49

Shortcodes 3

[myfaves-add] includes\shortcodes\myfaves-shortcodes.php:171
[myfaves-list] includes\shortcodes\myfaves-shortcodes.php:172
[myfaves-tags] includes\shortcodes\myfaves-shortcodes.php:173
WordPress Hooks 17
actionadmin_menuadmin\myfaves-settings.php:3
actionadmin_initadmin\myfaves-settings.php:9
actionplugins_loadedincludes\class-myfaves.php:149
actionadmin_enqueue_scriptsincludes\class-myfaves.php:164
actionadmin_enqueue_scriptsincludes\class-myfaves.php:165
actionwp_enqueue_scriptsincludes\class-myfaves.php:180
actionwp_enqueue_scriptsincludes\class-myfaves.php:181
actionwp_headincludes\functions.php:103
actioninitincludes\init.php:64
actionload-post.phpincludes\init.php:66
actionload-post-new.phpincludes\init.php:67
actionadd_meta_boxesincludes\init.php:72
actionsave_postincludes\init.php:74
filterpost_classincludes\init.php:159
actioninitincludes\init.php:184
actioninitincludes\shortcodes\myfaves-shortcodes.php:178
filterplugin_row_metamyfaves.php:61
Maintenance & Trust

My Faves for WP Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 4, 2022
PHP min version7.0
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

My Faves for WP Developer Profile

Sana Azmeh

2 plugins · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect My Faves for WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/my-faves/css/myfaves-admin.css/wp-content/plugins/my-faves/js/myfaves-admin.js
Script Paths
/wp-content/plugins/my-faves/js/myfaves-admin.js
Version Parameters
myfaves-admin?ver=1.2.5

HTML / DOM Fingerprints

CSS Classes
myfaves-fav-icon
Data Attributes
data-fave-iddata-nonce
JS Globals
myfaves
FAQ

Frequently Asked Questions about My Faves for WP