
My Plugin Information – Fetch Data from WordPress.org Security & Risk Analysis
wordpress.org/plugins/my-plugin-informationFetch plugin data from WordPress.org using a simple shortcode. Shows version, installs, ratings, and more. Cached for speed, auto-updated hourly.
Is My Plugin Information – Fetch Data from WordPress.org Safe to Use in 2026?
Generally Safe
Score 100/100My Plugin Information – Fetch Data from WordPress.org has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the "my-plugin-information" plugin v1.0.0 exhibits a strong security posture. The code analysis reveals no dangerous functions, no raw SQL queries, and all output is properly escaped. Furthermore, there are no file operations, external HTTP requests, or bundled libraries to consider. This indicates a developer who is adhering to many secure coding best practices. The absence of known CVEs and a clean vulnerability history further strengthens this positive assessment.
However, there are some areas that warrant attention. The complete absence of nonce checks and capability checks is a significant concern, especially given the presence of a shortcode, which can be a potential entry point. While the static analysis did not identify any specific taint flows or unprotected entry points, the lack of these fundamental security mechanisms leaves the plugin vulnerable to certain types of attacks if the shortcode were to process user-supplied data without proper validation or authorization. The overall conclusion is that while the plugin has a solid foundation in terms of code quality, the oversight in implementing nonce and capability checks represents a critical gap that needs to be addressed to ensure robust security.
Key Concerns
- Missing nonce checks
- Missing capability checks
My Plugin Information – Fetch Data from WordPress.org Security Vulnerabilities
My Plugin Information – Fetch Data from WordPress.org Code Analysis
Output Escaping
My Plugin Information – Fetch Data from WordPress.org Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
My Plugin Information – Fetch Data from WordPress.org Maintenance & Trust
Maintenance Signals
Community Trust
My Plugin Information – Fetch Data from WordPress.org Alternatives
Blog Members Directory shortcode
blog-members-directory-shortcode
The plugin enables any page or post author to include a Blog Members directory by using a shortcode.
WP.org Plugin Stats
wp-org-plugin-stats
WordPress.org Plugin Stats will be shown by Plugin API. You can use anywhere on your website
Business Listing
business-listing
Displays a list of businesses in box with a a description below an image. They can be filter by category and region.
GW Info Box
gw-info-box
Display live WordPress.org plugin information in a clean, styled box – using a simple shortcode.
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
My Plugin Information – Fetch Data from WordPress.org Developer Profile
7 plugins · 13K total installs
How We Detect My Plugin Information – Fetch Data from WordPress.org
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[mpi slug='{any}' field='{any}']