
oik Security & Risk Analysis
wordpress.org/plugins/oikOver 80 advanced, powerful shortcodes, and 9 blocks for displaying the content of your WordPress website.
Is oik Safe to Use in 2026?
Generally Safe
Score 95/100oik has a strong security track record. Known vulnerabilities have been patched promptly.
The oik plugin v4.15.4 presents a mixed security posture. While it demonstrates good practices such as 100% usage of prepared statements for SQL queries and a history of having all reported CVEs patched, there are significant concerns identified in the static analysis. Specifically, a substantial portion of the attack surface, comprising 3 out of 4 AJAX handlers, lacks proper authentication checks. This opens the door for unauthorized actions if these handlers can be triggered by unauthenticated users. Furthermore, the taint analysis reveals one high-severity flow with unsanitized input, indicating a potential for vulnerabilities even if not explicitly detailed in the CVE history. The plugin's history of 7 medium-severity CVEs, particularly those related to Cross-Site Request Forgery, Missing Authorization, and Cross-site Scripting, suggests a pattern of past weaknesses in input validation and authorization mechanisms. Although currently unpatched vulnerabilities are zero, the presence of unsanitized taint flows and unprotected entry points points to ongoing risks that require immediate attention. The plugin needs to address the unprotected AJAX endpoints and ensure all sensitive operations are adequately secured with robust authorization and input sanitization to improve its overall security.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow with unsanitized input
- Taint flows with unsanitized paths
- Missing nonce checks on entry points
- Medium severity CVE history pattern
- 55% of outputs properly escaped
oik Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
oik <= 4.15.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
oik <= 4.15.2 - Reflected Cross-Site Scripting
oik <= 4.15.2 - Cross-Site Request Forgery
oik <= 4.15.1 - Missing Authorization
oik <= 4.12.0 - Cross-Site Request Forgery
oik <= 4.10.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via bw_button Shortcode
oik <= 4.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
oik Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
oik Attack Surface
AJAX Handlers 4
WordPress Hooks 76
Maintenance & Trust
oik Maintenance & Trust
Maintenance Signals
Community Trust
oik Alternatives
Uix Shortcodes
uix-shortcodes
Uix Shortcodes brings an amazing set of beautiful and useful elements to your site that lets you do nifty things with very little effort.
Dev Content Blocks
dev-content-blocks
Content blocks for global content, with revisions. Use HTML without formatting being broken. Not only for devs.
Shortcodes – Advanced Shortcode Manager
advanced-shortcodes
Shortcodes - Advanced Shortcode Manager is a powerful and user-friendly WordPress plugin designed to help you manage shortcodes across your website.
oik-css
oik-css
Allows internal CSS styling to be included in the content of the page.
MIR blocks and shortcodes
mir-blocks-and-shortcodes
It's a block / shortcode toolbox which makes your wordpress live much easier.
oik Developer Profile
16 plugins · 7K total installs
How We Detect oik
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oik/oik.cssoik/oik.css?ver=HTML / DOM Fingerprints
/wp-json/oik/v1