orcas Responsive Wiki Security & Risk Analysis

wordpress.org/plugins/orcas-responsive-wiki

Buddypress wiki where registered users in the frontend can edit the same document after each other.

10 active installs v1.2.0 PHP 5.5+ WP 3.3+ Updated Sep 20, 2018
buddypressdocumentseditresponsivewiki
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is orcas Responsive Wiki Safe to Use in 2026?

Generally Safe

Score 85/100

orcas Responsive Wiki has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The orcas-responsive-wiki plugin v1.2.0 exhibits a mixed security posture. While it demonstrates good practices in SQL query handling by using prepared statements exclusively and has no recorded vulnerability history, several areas raise significant concerns. The plugin exposes a substantial attack surface, with 7 out of 11 AJAX handlers lacking authentication checks. This is a critical oversight, as it allows unauthenticated users to potentially trigger plugin functionality, leading to unpredictable behavior or even exploitation if combined with other vulnerabilities.

Furthermore, the taint analysis reveals 5 flows with unsanitized paths, indicating a potential for path traversal or manipulation vulnerabilities, although the static analysis did not flag these as critical or high severity. The presence of the `exec` function, a dangerous function, in the code also warrants careful consideration, as its misuse can lead to arbitrary code execution. The limited capability checks and a significant portion of unescaped output further compound these risks, making the plugin susceptible to cross-site scripting (XSS) attacks. The lack of historical vulnerabilities is positive but should not be a reason to overlook the present risks identified in the static analysis.

In conclusion, while the plugin benefits from secure SQL practices and a clean vulnerability history, the numerous unprotected AJAX endpoints, unsanitized path flows, and the presence of dangerous functions create a notable security risk. The unescaped output and limited capability checks further weaken its security. Mitigation efforts should prioritize addressing the authentication and sanitization issues within the AJAX handlers and taint flows.

Key Concerns

  • Unprotected AJAX handlers
  • Unsanitized paths in taint flows
  • Dangerous function 'exec' present
  • Low percentage of properly escaped output
  • Limited capability checks
Vulnerabilities
None known

orcas Responsive Wiki Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

orcas Responsive Wiki Code Analysis

Dangerous Functions
2
Raw SQL Queries
0
2 prepared
Unescaped Output
52
58 escaped
Nonce Checks
5
Capability Checks
1
File Operations
10
External Requests
4
Bundled Libraries
0

Dangerous Functions Found

execexec("cp -rf $path" . DIRECTORY_SEPARATOR . "cache" . DIRECTORY_SEPARATOR . "$slugName $path", $out)include\Upgrade\UpdateService.php:206
execexec("rm -rf $path" . DIRECTORY_SEPARATOR . "cache");include\Upgrade\UpdateService.php:209

SQL Query Safety

100% prepared2 total queries

Output Escaping

53% escaped110 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

10 flows5 with unsanitized paths
newWikiButton (core\ShortCode.php:145)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

orcas Responsive Wiki Attack Surface

Entry Points18
Unprotected7

AJAX Handlers 11

authwp_ajax_wiki_edit_categorycore\Category\Category.php:29
noprivwp_ajax_wiki_edit_categorycore\Category\Category.php:30
authwp_ajax_wiki_searchcore\Search\Search.php:25
noprivwp_ajax_wiki_searchcore\Search\Search.php:26
authwp_ajax_wiki_load_formcore\ShortCode.php:30
noprivwp_ajax_wiki_load_formcore\ShortCode.php:31
authwp_ajax_orcas-naggerinclude\Nagger\Nagger.php:29
authwp_ajax_wiki_page_editorcas-responsive-wiki.php:107
noprivwp_ajax_wiki_page_editorcas-responsive-wiki.php:108
authwp_ajax_wiki_pageorcas-responsive-wiki.php:110
noprivwp_ajax_wiki_pageorcas-responsive-wiki.php:111

Shortcodes 7

[wiki_add_create_button] core\ShortCode.php:22
[wiki_add_back_button] core\ShortCode.php:23
[wiki_add_form_back_button] core\ShortCode.php:24
[wiki_add_create_link] core\ShortCode.php:26
[wiki_add_back_link] core\ShortCode.php:27
[wiki_add_form_back_link] core\ShortCode.php:28
[view_wiki] orcas-responsive-wiki.php:62
WordPress Hooks 30
actionwiki_settingscore\Category\Category.php:15
actionresponsive_wiki_buddypress_settingscore\Category\Category.php:16
actionresponsive_wiki_buddypress_settings_savecore\Category\Category.php:17
actionwiki_settings_savecore\Category\Category.php:18
filterwiki_before_groupcore\Category\Category.php:19
filterwiki_after_groupcore\Category\Category.php:20
filterwiki_add_form_fieldscore\Category\Category.php:21
actionwiki_add_js_extensioncore\Category\Category.php:22
actionwiki_list_templatecore\Category\Category.php:23
actionwiki_after_savecore\Category\Category.php:24
actionwiki_before_listcore\Category\Category.php:25
actionwiki_initcore\Category\Category.php:27
filterpre_get_postscore\Search\Search.php:19
actionwiki_before_listcore\Search\Search.php:20
actionwiki_after_listcore\Search\Search.php:21
filterwiki_before_groupcore\Search\Search.php:22
actioninitcore\wiki.php:29
actionplugins_loadedinclude\autoload.php:23
actionadmin_noticesinclude\Nagger\Nagger.php:26
actionadmin_enqueue_scriptsinclude\Nagger\Nagger.php:27
actionadmin_menuinclude\Upgrade\Upgrade.php:27
actionupgrader_process_completeinclude\Upgrade\Upgrade.php:28
filterhttp_request_argsinclude\Upgrade\Upgrade.php:29
actioninitinclude\Upgrade\Upgrade.php:30
actionplugins_loadedorcas-responsive-wiki.php:31
actionshutdownorcas-responsive-wiki.php:102
actioninitorcas-responsive-wiki.php:104
actionadmin_menuorcas-responsive-wiki.php:105
actionwiki_displayorcas-responsive-wiki.php:113
actionelementor/initorcas-responsive-wiki.php:115
Maintenance & Trust

orcas Responsive Wiki Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 20, 2018
PHP min version5.5
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

orcas Responsive Wiki Developer Profile

orcasdev

2 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect orcas Responsive Wiki

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orcas-responsive-wiki/core/js/initForm.js/wp-content/plugins/orcas-responsive-wiki/core/css/form.css/wp-content/plugins/orcas-responsive-wiki/core/css/categoryBox.css/wp-content/plugins/orcas-responsive-wiki/core/js/categoryBox.js
Script Paths
/wp-content/plugins/orcas-responsive-wiki/core/js/initForm.js/wp-content/plugins/orcas-responsive-wiki/core/js/categoryBox.js

HTML / DOM Fingerprints

CSS Classes
category-bread-crumbwiki-list
Data Attributes
data-key
REST Endpoints
/wp-json/orcas-responsive-wiki/v1/wiki
Shortcode Output
[view_wiki]
FAQ

Frequently Asked Questions about orcas Responsive Wiki