Ozh' Avatar Popup Security & Risk Analysis
wordpress.org/plugins/ozh-avatar-popupAdd CSS popups next to mailto links or next to any word. Can be any custom image, and has gravatar support.
Is Ozh' Avatar Popup Safe to Use in 2026?
Generally Safe
Score 85/100Ozh' Avatar Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the ozh-avatar-popup plugin version 1.1 presents a mixed security posture. The plugin's attack surface appears to be minimal with no identified AJAX handlers, REST API routes, shortcodes, or cron events, which is a positive indicator. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and bundled libraries is also commendable. However, significant concerns arise from the code analysis regarding data handling. The plugin performs SQL queries without using prepared statements, which is a serious risk for SQL injection vulnerabilities. Additionally, all identified output is not properly escaped, creating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The lack of any nonce or capability checks further exacerbates these risks by allowing any authenticated user, potentially with low privileges, to trigger these vulnerable operations.
Key Concerns
- SQL queries without prepared statements
- Unescaped output
- Missing nonce checks
- Missing capability checks
Ozh' Avatar Popup Security Vulnerabilities
Ozh' Avatar Popup Code Analysis
SQL Query Safety
Output Escaping
Ozh' Avatar Popup Attack Surface
WordPress Hooks 3
Maintenance & Trust
Ozh' Avatar Popup Maintenance & Trust
Maintenance Signals
Community Trust
Ozh' Avatar Popup Alternatives
Easy Gravatars
easygravatars
Add Gravatars to your comments without modifying any template files. Just activate, and you're done!
Top Commentators Widget
top-commentators-widget
Adds a sidebar widget to show the top commentators in your WP site. Demo: http://demo.webgrrrl.net
Polygon Recent Comments With Avatar
polygon-recent-comments-with-avatar
Polygon Recent Comments With Avatar: Recent comments with avatar support, including Gravatar, date, username, user link, and scrollbar.
Default Gravatar Sans
default-gravatar-sans
Disables Gravatar.com avatar, and allows one local default avatar image for users without avatar in his profile.
Mirror Gravatar
mirror-gravatar
Locally mirror commenters' Gravatar or Mastodon profile images.
Ozh' Avatar Popup Developer Profile
27 plugins · 5K total installs
How We Detect Ozh' Avatar Popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
avatarpopdata-gravatar_iddata-defaultdata-size<span class="avatarpop"><a href="mailto:<img src="http://www.gravatar.com/avatar.php?