My Plugin Information – Fetch Data from WordPress.org Security & Risk Analysis

wordpress.org/plugins/my-plugin-information

Fetch plugin data from WordPress.org using a simple shortcode. Shows version, installs, ratings, and more. Cached for speed, auto-updated hourly.

10 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Jul 27, 2025
directoryplugin-dataplugin-infoshortcodewordpress-org
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is My Plugin Information – Fetch Data from WordPress.org Safe to Use in 2026?

Generally Safe

Score 100/100

My Plugin Information – Fetch Data from WordPress.org has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

Based on the static analysis and vulnerability history, the "my-plugin-information" plugin v1.0.0 exhibits a strong security posture. The code analysis reveals no dangerous functions, no raw SQL queries, and all output is properly escaped. Furthermore, there are no file operations, external HTTP requests, or bundled libraries to consider. This indicates a developer who is adhering to many secure coding best practices. The absence of known CVEs and a clean vulnerability history further strengthens this positive assessment.

However, there are some areas that warrant attention. The complete absence of nonce checks and capability checks is a significant concern, especially given the presence of a shortcode, which can be a potential entry point. While the static analysis did not identify any specific taint flows or unprotected entry points, the lack of these fundamental security mechanisms leaves the plugin vulnerable to certain types of attacks if the shortcode were to process user-supplied data without proper validation or authorization. The overall conclusion is that while the plugin has a solid foundation in terms of code quality, the oversight in implementing nonce and capability checks represents a critical gap that needs to be addressed to ensure robust security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

My Plugin Information – Fetch Data from WordPress.org Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

My Plugin Information – Fetch Data from WordPress.org Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

My Plugin Information – Fetch Data from WordPress.org Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mpi] includes\class-my-plugin-information.php:35
WordPress Hooks 1
actioninitincludes\class-my-plugin-information.php:25
Maintenance & Trust

My Plugin Information – Fetch Data from WordPress.org Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 27, 2025
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

My Plugin Information – Fetch Data from WordPress.org Developer Profile

Harish Chouhan

7 plugins · 13K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
1906 days
View full developer profile
Detection Fingerprints

How We Detect My Plugin Information – Fetch Data from WordPress.org

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[mpi slug='{any}' field='{any}']
FAQ

Frequently Asked Questions about My Plugin Information – Fetch Data from WordPress.org