
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/oracle-cardsInteractive Card Deck Plugin for WordPress
Is Oracle Cards Lite – Interactive Card Deck Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 99/100Oracle Cards Lite – Interactive Card Deck Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'oracle-cards' plugin, version 1.2.7, exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries, has a high percentage of properly escaped output, and performs nonce and capability checks on a majority of its entry points. There are no reported dangerous functions, file operations, or external HTTP requests, which are excellent indicators of secure coding. However, a significant concern is the presence of four unprotected AJAX handlers, which represent a substantial attack surface that could be exploited by unauthenticated users.
The vulnerability history indicates a past medium-severity Cross-Site Scripting (XSS) vulnerability, which, while currently patched, suggests a recurring pattern of input sanitization issues. The single flow with an unsanitized path identified in the taint analysis, despite not being classified as critical or high severity, aligns with this XSS history and warrants attention as a potential vector for indirect data compromise or manipulation.
Overall, while the plugin has strong foundations in SQL and output handling, the unprotected AJAX endpoints and the historical XSS vulnerability present clear risks. Addressing these specific areas would significantly improve the plugin's security.
Key Concerns
- Unprotected AJAX handlers
- Flow with unsanitized paths
- Past medium severity XSS vulnerability
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Oracle Cards Lite <= 1.2.1 - Reflected Cross-Site Scripting
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress Release Timeline
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress Attack Surface
AJAX Handlers 6
Shortcodes 3
WordPress Hooks 33
Maintenance & Trust
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress Alternatives
Tarot, Oracle cards, Tarot readings, Tarokina
tarokina-free
The best tarot plugin for wordpress. Intuitive and easy to use. Provides accurate tarot readings.
Payment Plugins for PayPal WooCommerce
pymntpl-paypal-woocommerce
Developed exclusively between Payment Plugins and PayPal, PayPal for WooCommerce integrates with PayPal's newest API's.
PW WooCommerce Gift Cards
pw-woocommerce-gift-cards
Sell gift cards to your WooCommerce store, in just a few minutes!
Payment Gateway for PayPal on WooCommerce
woo-paypal-gateway
PayPal, Credit/Debit Cards, Google Pay, Apple Pay, Pay Later, Venmo, SEPA, iDEAL, Mercado Pago, Bancontact & more - by an official PayPal Partner
YITH WooCommerce Gift Cards
yith-woocommerce-gift-cards
The essential tool for selling gift cards in your store, increasing your conversion rate and attracting new customers.
Oracle Cards Lite – Interactive Card Deck Plugin for WordPress Developer Profile
1 plugin · 300 total installs
How We Detect Oracle Cards Lite – Interactive Card Deck Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oracle-cards/assets-1.7.0/css/style.css/wp-content/plugins/oracle-cards/assets-1.7.0/js/scripts.js/wp-content/plugins/oracle-cards/assets-1.7.0/js/scripts.jsoracle-cards/assets-1.7.0/css/style.css?ver=oracle-cards/assets-1.7.0/js/scripts.js?ver=HTML / DOM Fingerprints
window.eos_cards_ajax_url[oracle_cards]