
My Github Security & Risk Analysis
wordpress.org/plugins/my-githubA simple and nice WordPress plugin that can track your github's profile.
Is My Github Safe to Use in 2026?
Generally Safe
Score 85/100My Github has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "my-github" plugin version 1.2.4 exhibits a generally good security posture based on the provided static analysis. There are no identified critical or high-severity vulnerabilities in taint analysis, and the plugin has no recorded vulnerability history, suggesting a proactive approach to security by its developers. The high percentage of properly escaped output (94%) and the presence of nonce checks are positive indicators. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its apparent safety.
However, there are areas of concern. The single SQL query is not using prepared statements, which presents a potential risk for SQL injection if the query's inputs are not rigorously validated and escaped server-side. While the number of external HTTP requests is low (3), any interaction with external services can introduce risks if not handled securely. The complete absence of capability checks is a significant weakness. Without capability checks, any user, regardless of their role or permissions, could potentially interact with the plugin's functionality, opening it up to unauthorized access or manipulation if any of its components have sensitive actions.
In conclusion, the "my-github" plugin demonstrates commendable security practices in output escaping and managing its attack surface. Nevertheless, the lack of capability checks and the use of raw SQL queries without prepared statements represent significant security weaknesses that should be addressed to achieve a more robust security posture. The absence of historical vulnerabilities is promising but should not overshadow the identified code-level risks.
Key Concerns
- Raw SQL query without prepared statements
- No capability checks for any entry points
My Github Security Vulnerabilities
My Github Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
My Github Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
My Github Maintenance & Trust
Maintenance Signals
Community Trust
My Github Alternatives
Show developer profile
show-git-developer-profile
A plugin to fetch and exhibit profile information and list repositories of a given github user.
WP Reroute Email
wp-reroute-email
This plugin reroutes all outgoing emails from a WordPress site (sent using the wp_mail() function) to a predefined configurable email address.
Ray
spatie-ray
Easily debug WordPress sites using Ray.
Asset Queue Manager
asset-queue-manager
A tool for experienced frontend performance engineers to take control over the scripts and styles enqueued on their site.
Discourage Search Engines Notifier
discourage-search-engines-notifier
Shows an admin bar icon indicating your site's search engine visibility status.
My Github Developer Profile
3 plugins · 240 total installs
How We Detect My Github
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/my-github/assets/my_github_qtags.min.js/wp-content/plugins/my-github/assets/my_github.min.css/wp-content/plugins/my-github/assets/grids-min.css/wp-content/plugins/my-github/assets/fontawesome-free-5.15.3/css/all.min.css/wp-content/plugins/my-github/appsero/src/Client.phpmy-github/assets/my_github_qtags.min.js?ver=my-github/assets/my_github.min.css?ver=my-github/assets/grids-min.css?ver=my-github/assets/fontawesome-free-5.15.3/css/all.min.css?ver=HTML / DOM Fingerprints
my-github-profilemy-github-repo<!-- Menu class file --><!-- Project My Github -->data-usernamedata-repo-countmy_github_opts[my_github]