News PhotoCard Pro Security & Risk Analysis

wordpress.org/plugins/news-photocard-pro

Create customizable 1080×1080 photo cards from posts with templates, Elementor widget, and shortcode support.

700 active installs v3.6.0 PHP 7.4+ WP 5.8+ Updated Nov 2, 2025
designelementornewssocial-mediatemplate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is News PhotoCard Pro Safe to Use in 2026?

Generally Safe

Score 100/100

News PhotoCard Pro has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The news-photocard-pro plugin version 3.6.0 demonstrates a strong security posture based on the provided static analysis. It effectively utilizes prepared statements for all SQL queries and exhibits a high percentage of properly escaped output, significantly reducing the risk of SQL injection and cross-site scripting (XSS) vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design. Furthermore, the presence of nonce checks on all identified AJAX entry points is a positive indicator of protection against CSRF attacks.

While the static analysis reveals no immediate critical or high-severity issues, the zero capability checks on AJAX handlers represent a potential area for concern. Although nonce checks are present, the lack of explicit capability checks means that any authenticated user, regardless of their role or permissions, could potentially trigger these AJAX actions. This could be a weakness if these actions are intended for privileged users only. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting a commitment to security or a lack of prior exploitation. However, this historical absence of vulnerabilities should not lead to complacency, as new vulnerabilities can emerge.

In conclusion, news-photocard-pro v3.6.0 is well-implemented with several robust security practices in place, particularly concerning SQL and output handling. The primary area for improvement lies in implementing capability checks for its AJAX handlers to ensure proper authorization. The lack of historical vulnerabilities is a positive sign, but ongoing vigilance and security audits are always recommended.

Key Concerns

  • AJAX handlers lack capability checks
Vulnerabilities
None known

News PhotoCard Pro Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

News PhotoCard Pro Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
21 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped23 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_page (includes\class-photocard-core.php:121)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

News PhotoCard Pro Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 3

authwp_ajax_udnpc_get_cardincludes\class-photocard-core.php:16
noprivwp_ajax_udnpc_get_cardincludes\class-photocard-core.php:17
authwp_ajax_udnpcv36_get_saved_optionsincludes\class-photocard-core.php:18

Shortcodes 1

[news_photocard_button] includes\class-photocard-core.php:14
WordPress Hooks 5
actionadmin_menuincludes\class-photocard-core.php:10
actionadmin_enqueue_scriptsincludes\class-photocard-core.php:11
actionwp_enqueue_scriptsincludes\class-photocard-core.php:12
actionthe_contentincludes\class-photocard-core.php:13
actionelementor/widgets/registernews-photocard-pro.php:40
Maintenance & Trust

News PhotoCard Pro Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 2, 2025
PHP min version7.4
Downloads66K

Community Trust

Rating0/100
Number of ratings0
Active installs700
Developer Profile

News PhotoCard Pro Developer Profile

Rasedul Haque Rumi

8 plugins · 3K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect News PhotoCard Pro

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/news-photocard-pro/admin/admin.css/wp-content/plugins/news-photocard-pro/admin/admin.js
Script Paths
/wp-content/plugins/news-photocard-pro/admin/admin.js
Version Parameters
news-photocard-pro/admin/admin.css?ver=news-photocard-pro/admin/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
udnpc-settings-wrapudnpc-template-previewudnpc-template-selectorudnpc-template-fieldsudnpc-settings-sectionudnpc-color-picker-wrapudnpc-input-rowudnpc-template-field+2 more
HTML Comments
<!-- News PhotoCard Pro Settings Page --><!-- End News PhotoCard Pro Settings Page -->
Data Attributes
data-udnpc-templatedata-udnpc-template-key
JS Globals
UDNPCAdmin
REST Endpoints
/wp-json/udnpc/v1/get-card/wp-json/udnpc/v1/get-saved-options
Shortcode Output
[news_photocard_button]
FAQ

Frequently Asked Questions about News PhotoCard Pro