OpenGraphiq Lite Security & Risk Analysis

wordpress.org/plugins/opengraphiq-lite

WordPress Social Image Generator - Allows you to automatically generate social share images for your WordPress content.

20 active installs v1.0.0 PHP 7.0+ WP 4.5+ Updated Nov 9, 2023
facebooklinkedinsharetwittertwitter-card
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OpenGraphiq Lite Safe to Use in 2026?

Generally Safe

Score 85/100

OpenGraphiq Lite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The OpengraphIQ Lite v1.0.0 plugin exhibits a concerning security posture primarily due to its unprotected AJAX handlers. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and having no recorded vulnerabilities, the presence of four AJAX handlers without authentication checks represents a significant attack vector. This means that any user, including unauthenticated visitors, could potentially trigger these functions, leading to unintended consequences or unauthorized actions if the handlers themselves have exploitable logic. The static analysis shows no critical or high severity taint flows, and output escaping is at a moderate level (62% properly escaped), which is a weakness but not critical in isolation given the absence of other major issues. The lack of any historical vulnerabilities is a positive sign, suggesting a generally stable codebase, but it does not mitigate the immediate risks posed by the unprotected entry points.

Key Concerns

  • Unprotected AJAX handlers
  • Moderate output escaping
Vulnerabilities
None known

OpenGraphiq Lite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

OpenGraphiq Lite Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
53
85 escaped
Nonce Checks
7
Capability Checks
9
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

62% escaped138 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
opengraphiq_save_templates_field_meta (admin\class-opengraphiq-admin.php:573)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

OpenGraphiq Lite Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_bulk_ajaxincludes\class-opengraphiq.php:144
authwp_ajax_bulk_ajax_create_photoincludes\class-opengraphiq.php:145
authwp_ajax_test_ajaxincludes\class-opengraphiq.php:146
authwp_ajax_save_single_post_metaincludes\class-opengraphiq.php:147
WordPress Hooks 23
filterwp_import_postsadmin\class-opengraphiq-admin.php:282
filtermanage_opengraphiqtemplates_posts_columnsadmin\class-opengraphiq-admin.php:333
actionmanage_opengraphiqtemplates_posts_custom_columnadmin\class-opengraphiq-admin.php:337
actionplugins_loadedincludes\class-opengraphiq.php:119
actionadmin_enqueue_scriptsincludes\class-opengraphiq.php:134
actionadmin_enqueue_scriptsincludes\class-opengraphiq.php:135
actioninitincludes\class-opengraphiq.php:139
actionedit_form_after_titleincludes\class-opengraphiq.php:140
actionsave_postincludes\class-opengraphiq.php:141
actionadmin_menuincludes\class-opengraphiq.php:142
actionadmin_noticesincludes\class-opengraphiq.php:143
actionadmin_initincludes\class-opengraphiq.php:148
actionadd_meta_boxesincludes\class-opengraphiq.php:149
actionsave_postincludes\class-opengraphiq.php:150
actionrestrict_manage_postsincludes\class-opengraphiq.php:151
actionquick_edit_custom_boxincludes\class-opengraphiq.php:152
actionwp_trash_postincludes\class-opengraphiq.php:153
actiondo_meta_boxesincludes\class-opengraphiq.php:154
filteruser_can_richeditincludes\class-opengraphiq.php:156
filterparse_queryincludes\class-opengraphiq.php:157
actionwp_headincludes\class-opengraphiq.php:174
actionwp_headincludes\class-opengraphiq.php:175
actionwp_headincludes\class-opengraphiq.php:176
Maintenance & Trust

OpenGraphiq Lite Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 9, 2023
PHP min version7.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

OpenGraphiq Lite Developer Profile

boldthemes

8 plugins · 69K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
118 days
View full developer profile
Detection Fingerprints

How We Detect OpenGraphiq Lite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/opengraphiq-lite/css/opengraphiq-admin.css/wp-content/plugins/opengraphiq-lite/css/opengraphiq-icon.css/wp-content/plugins/opengraphiq-lite/js/opengraphiq-admin.js/wp-content/plugins/opengraphiq-lite/js/html2canvas.min.js/wp-content/plugins/opengraphiq-lite/js/opengraphiq-single-post.js
Script Paths
js/opengraphiq-admin.jsjs/html2canvas.min.jsjs/opengraphiq-single-post.js
Version Parameters
opengraphiq-admin.css?ver=opengraphiq-icon.css?ver=opengraphiq-admin.js?ver=html2canvas.min.js?ver=opengraphiq-single-post.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-opengraphiq-ajaxurl
JS Globals
opengraphiqJSopengraphiqAjaxadminJStranslations
FAQ

Frequently Asked Questions about OpenGraphiq Lite