ORQADESIGN Bluesky Feed Security & Risk Analysis

wordpress.org/plugins/orqadesign-bluesky-feed

Easily display and cache the latest posts from a Bluesky user using a shortcode.

30 active installs v1.0.1 PHP 7.4+ WP 5.5+ Updated Feb 19, 2026
blueskybluesky-feedembedfeedsocial-media
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is ORQADESIGN Bluesky Feed Safe to Use in 2026?

Generally Safe

Score 100/100

ORQADESIGN Bluesky Feed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'orqadesign-bluesky-feed' plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The code adheres to several best practices, including using prepared statements for all SQL queries and properly escaping all output. There are no identified critical or high severity taint flows, no dangerous functions, and no file operations, which significantly reduces the risk of common injection and manipulation vulnerabilities. The plugin also has no known historical vulnerabilities, suggesting a history of secure development.

However, there are areas that warrant attention. The absence of nonce checks and capability checks on the identified shortcode is a significant concern. While the attack surface is small with only one entry point (the shortcode), and no AJAX or REST API routes were found, this single unprotected shortcode could potentially be exploited. The presence of two external HTTP requests without explicit mention of their handling or security considerations also represents a potential, albeit less defined, risk. The lack of any recorded vulnerability history, while positive, doesn't guarantee future security and should not lead to complacency.

In conclusion, the plugin demonstrates a strong foundation in secure coding practices for SQL and output handling. The primary risk lies in the unprotected shortcode and the external HTTP requests. Addressing these specific points would further strengthen the plugin's security, making it a more robust and trustworthy component.

Key Concerns

  • Unprotected shortcode
  • External HTTP requests (2)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

ORQADESIGN Bluesky Feed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ORQADESIGN Bluesky Feed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped22 total outputs
Attack Surface

ORQADESIGN Bluesky Feed Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bluesky_feed] orqadesign-bluesky-feed.php:10
WordPress Hooks 3
actionadmin_menuorqadesign-bluesky-feed.php:189
actionadmin_initorqadesign-bluesky-feed.php:253
actionwp_enqueue_scriptsorqadesign-bluesky-feed.php:277
Maintenance & Trust

ORQADESIGN Bluesky Feed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.4
Downloads548

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

ORQADESIGN Bluesky Feed Developer Profile

orqadesign

1 plugin · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ORQADESIGN Bluesky Feed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orqadesign-bluesky-feed/assets/Bluesky_Logo.svg.png

HTML / DOM Fingerprints

CSS Classes
bluesky-header-wrapperbluesky-headerbluesky-feedbluesky-postbluesky-image
Data Attributes
data-bsky-handle
REST Endpoints
/xrpc/com.atproto.server.createSession/xrpc/app.bsky.feed.getAuthorFeed
Shortcode Output
No Bluesky handle specified.Bluesky credentials not set. Please check plugin settings.Could not authenticate with Bluesky.Could not load feed.
FAQ

Frequently Asked Questions about ORQADESIGN Bluesky Feed