
OKR – Objectives Key Results Security & Risk Analysis
wordpress.org/plugins/objectives-key-results-okrObjectives Key Results - OKR Plugin for WordPress to set goals and objectives. Simply create your objectives and key results to manage tasks easily.
Is OKR – Objectives Key Results Safe to Use in 2026?
Generally Safe
Score 100/100OKR – Objectives Key Results has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "objectives-key-results-okr" plugin v1.1.0 reveals a generally strong security posture. The plugin demonstrates good practices by avoiding dangerous functions, using prepared statements exclusively for SQL queries, and having a high percentage of properly escaped output. The absence of file operations and external HTTP requests further reduces the attack surface. Crucially, there are no recorded vulnerabilities (CVEs) for this plugin, indicating a history of stable and secure development or a lack of historical scrutiny that could mask latent issues.
However, there are areas for improvement. The plugin lacks capability checks on its entry points, which could potentially expose functionality to unauthorized users if specific roles are not explicitly restricted elsewhere. While there's a nonce check present, its effectiveness in conjunction with the lack of capability checks needs careful consideration. The absence of taint analysis results is also a point of concern, as it means potential vulnerabilities related to unsanitized data flows may not have been identified by the analysis performed.
In conclusion, the plugin exhibits strengths in its secure coding practices regarding data handling and SQL injection prevention. The lack of known vulnerabilities is a significant positive. The primary areas of concern stem from the absence of capability checks on entry points and the incomplete nature of the taint analysis, suggesting a need for more comprehensive security auditing to ensure all potential risks are addressed.
Key Concerns
- Missing capability checks on entry points
- No taint analysis results provided
OKR – Objectives Key Results Security Vulnerabilities
OKR – Objectives Key Results Code Analysis
Output Escaping
OKR – Objectives Key Results Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
OKR – Objectives Key Results Maintenance & Trust
Maintenance Signals
Community Trust
OKR – Objectives Key Results Alternatives
Dashboard To-Do List
dashboard-to-do-list
A dashboard to-do list widget with the option to show the to-do list on the website. This is a great tool for web developers building a new website.
Zephyr Project Manager
zephyr-project-manager
Zephyr Project Manager is a modern, easy to use sophisticated project manager for WordPress.
Docket WP
docket-wp
The Docket WP plugin connects your Docket WP account into any WordPress installation. You will need a Docket WP account in order to use the plugin.
Todo Block
todo-block
Adds ToDo list block that shows checkboxes on frontend and backend of your site.
Todo for BuddyPress & BuddyBoss
bp-user-to-do-list
Transform your BuddyPress or BuddyBoss community into a powerful task management platform. Members can create personal todos, collaborate on group tas …
OKR – Objectives Key Results Developer Profile
3 plugins · 60 total installs
How We Detect OKR – Objectives Key Results
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.