
NIH Cancer Dictionary Security & Risk Analysis
wordpress.org/plugins/nih-cancer-dictionaryAdd NIH Cancer Dictionary Widget in the Sidebar of your Health and Medical Blog or Wesbite.
Is NIH Cancer Dictionary Safe to Use in 2026?
Generally Safe
Score 85/100NIH Cancer Dictionary has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nih-cancer-dictionary" plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding raw SQL queries and has no recorded vulnerability history, suggesting a generally secure development approach.
However, significant concerns arise from the static analysis. The presence of the `create_function` is a critical security anti-pattern due to its potential for arbitrary code execution. Furthermore, 100% of the plugin's output is unescaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks across all identified entry points (though zero in number) also indicates a potential for unauthorized actions if new entry points were to be added without proper security considerations.
The absence of known CVEs and a clean vulnerability history is a strong indicator of past diligence. Nevertheless, the identified code signals, particularly the dangerous function and unescaped output, present immediate risks that overshadow the lack of past issues. The plugin's strengths lie in its current lack of historical vulnerabilities and its use of prepared statements, but the identified static analysis issues require urgent attention.
Key Concerns
- Dangerous function 'create_function' used
- Output escaping missing on all outputs
- No nonce checks on entry points
- No capability checks on entry points
NIH Cancer Dictionary Security Vulnerabilities
NIH Cancer Dictionary Release Timeline
NIH Cancer Dictionary Code Analysis
Dangerous Functions Found
Output Escaping
NIH Cancer Dictionary Attack Surface
WordPress Hooks 1
Maintenance & Trust
NIH Cancer Dictionary Maintenance & Trust
Maintenance Signals
Community Trust
NIH Cancer Dictionary Alternatives
HIPAA FORMS – Add HIPAA Compliant Webforms to Your WordPress Website
codemonkeys-hipaa-forms
Add HIPAA Compliant web forms easily to your Wordpress website using the HIPAA FORMS SaaS Service and Caldera or Gravity Forms.
IDonate – Blood Donation, Request And Donor Management System
idonate
A complete WordPress system to handle blood donations, donor records, and urgent requests—ideal for hospitals, NGOs, and clinics.
Medical Before After Gallery
medical-before-after-gallery
A simple before-after image gallery plugin designed for medical professionals and healthcare practices.
Health & Medical Addons for KingComposer
health-and-medical-addons-for-kingcomposer
This plugin works best with Nilima Theme - 100% Free
Latest Canadian Healthcare Jobs sidebar widget
latest-canadian-healthcare-jobs-sidebar-widget
Displays a live map of Canada showing the latest jobs posted on the Hospital.ca medical job listing service
NIH Cancer Dictionary Developer Profile
4 plugins · 50 total installs
How We Detect NIH Cancer Dictionary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
http://www.cancer.gov/publishedcontent/Js/TermDictionaryWidgetEnglish.jsHTML / DOM Fingerprints
cancerdictionary<script language="javascript" type="text/javascript" src="http://www.cancer.gov/publishedcontent/Js/TermDictionaryWidgetEnglish.js"></script>