
NERD WP Plugin Security & Risk Analysis
wordpress.org/plugins/nerd-wpNERD (https://github.com/kermitt2/entity-fishing) is an application that allows to recognize and disambiguate named entities.
Is NERD WP Plugin Safe to Use in 2026?
Generally Safe
Score 85/100NERD WP Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nerd-wp" v1.2.5 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and avoiding file operations or external HTTP requests. The absence of recorded vulnerabilities and CVEs in its history suggests a generally stable and well-maintained codebase.
However, significant concerns arise from the static analysis. The plugin presents a single entry point via its REST API route, which completely lacks permission callbacks, making it accessible to unauthenticated users. Furthermore, only 28% of output is properly escaped, indicating a high potential for Cross-Site Scripting (XSS) vulnerabilities. While taint analysis shows no critical or high severity flows, the limited scope (0 flows analyzed) means this doesn't provide strong assurance of safety. The presence of the Guzzle library, if outdated, could also introduce risks, though the analysis doesn't specify its version.
In conclusion, "nerd-wp" v1.2.5 has strengths in its database query handling and lack of historical vulnerabilities. Nevertheless, the unprotected REST API route and widespread output unescaped are critical security weaknesses that require immediate attention to mitigate potential exploitation.
Key Concerns
- REST API route without permission callbacks
- Low percentage of properly escaped output
NERD WP Plugin Security Vulnerabilities
NERD WP Plugin Release Timeline
NERD WP Plugin Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
NERD WP Plugin Attack Surface
REST API Routes 1
WordPress Hooks 18
Maintenance & Trust
NERD WP Plugin Maintenance & Trust
Maintenance Signals
Community Trust
NERD WP Plugin Alternatives
No alternatives data available yet.
NERD WP Plugin Developer Profile
3 plugins · 90 total installs
How We Detect NERD WP Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nerd-wp/css/nerd-wp-admin.cssnerd-wp/css/nerd-wp-admin.css?ver=HTML / DOM Fingerprints
name="relaunch-nerd"<input type='text' name='Yoyo'>test</input>