
Organization chart Security & Risk Analysis
wordpress.org/plugins/organization-chartWordPress organization chart plugin is a nice and handy tool for creating simple and nice organizational charts. If you have any suggestions about the …
Is Organization chart Safe to Use in 2026?
Generally Safe
Score 96/100Organization chart has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The organization-chart plugin v1.7.6 presents a mixed security posture. While it demonstrates good practices such as a high percentage of properly escaped output, a significant number of prepared SQL statements, and no file operations or external HTTP requests, there are several areas of concern. The presence of an unprotected AJAX handler significantly expands the attack surface and is a direct entry point for unauthenticated malicious input. Taint analysis, though limited, did reveal flows with unsanitized paths, which, combined with the unprotected AJAX handler, could potentially lead to vulnerabilities if exploited correctly. The plugin's history of 5 CVEs, including one high-severity vulnerability and four medium-severity, particularly those related to Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Missing Authorization, indicates a pattern of past security weaknesses. Although there are no currently unpatched vulnerabilities, this history warrants vigilance. The overall risk is moderate, leaning towards concerning due to the unprotected AJAX endpoint and past vulnerability trends.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths
- Past high-severity vulnerability
- Multiple past medium-severity vulnerabilities
Organization chart Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Organization chart <= 1.5.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via title_input and node_description Parameters
Organization chart <= 1.4.4 - Authenticated (Admin+) Stored Cross-Site Scripting
Organization chart <= 1.4.4 - Cross-Site Request Forgery
Organization chart <= 1.4.1 - Cross-Site Request Forgery
Organization chart <= 1.4.1 - Missing Authorization
Organization chart Release Timeline
Organization chart Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Organization chart Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Organization chart Maintenance & Trust
Maintenance Signals
Community Trust
Organization chart Alternatives
Simple Staff List
simple-staff-list
A simple plugin to build and display a staff listing for your website.
Simple Org Chart
simple-org-chart
Create a simple jQuery Org Chart which will display your team or organisation structure in a hierarchical fashion, using easy drag and drop facilities …
Clicface Organi
clicface-organi
Create Org Charts easily in WordPress. A flexible and lightweight WordPress plugin, working with Clicface Trombi.
Interactive Organizational Chart
interactive-organizational-chart
A complete WordPress plugin for managing and displaying interactive organizational charts with admin and editor data upload and user-friendly viewing.
Business Directory Plugin – Easy Listing Directories for WordPress
business-directory-plugin
The easy Business Directory Plugin for WordPress. Build an easy team directory, member directory, staff directory, church directory, and more.
Organization chart Developer Profile
45 plugins · 52K total installs
How We Detect Organization chart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/organization-chart/admin/gutenberg/style.css/wp-content/plugins/organization-chart/admin/gutenberg/block.js/wp-content/plugins/organization-chart/admin/assets/js/alpha-color-picker.js/wp-content/plugins/organization-chart/admin/gutenberg/block.jsorganization-chart/admin/gutenberg/style.css?ver=organization-chart/admin/gutenberg/block.js?ver=organization-chart/admin/assets/js/alpha-color-picker.js?ver=HTML / DOM Fingerprints
wpda_org_chart_tree_pagewpda_org_chart_tree_themeswpda_org_chart_tree_popup_themeswpda_org_chart_tree_user_permissionswpda_org_chart_featured_pluginswpda_org_chart_featured_themeswpda_org_chart_hire_expertwpda_org_chart_user_permissions::get_allowed_page_permission('chart_page')wpda_org_chart_user_permissions::get_allowed_page_permission('chart_theme_page')wpda_org_chart_user_permissions::get_allowed_page_permission('chart_popup_page')wpda_org_chart_plugin_url