Ozh' Avatar Popup Security & Risk Analysis

wordpress.org/plugins/ozh-avatar-popup

Add CSS popups next to mailto links or next to any word. Can be any custom image, and has gravatar support.

10 active installs v1.1 PHP + WP 1.5+ Updated Sep 18, 2010
avatarcommentsgravatarozhpopup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ozh' Avatar Popup Safe to Use in 2026?

Generally Safe

Score 85/100

Ozh' Avatar Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the ozh-avatar-popup plugin version 1.1 presents a mixed security posture. The plugin's attack surface appears to be minimal with no identified AJAX handlers, REST API routes, shortcodes, or cron events, which is a positive indicator. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and bundled libraries is also commendable. However, significant concerns arise from the code analysis regarding data handling. The plugin performs SQL queries without using prepared statements, which is a serious risk for SQL injection vulnerabilities. Additionally, all identified output is not properly escaped, creating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The lack of any nonce or capability checks further exacerbates these risks by allowing any authenticated user, potentially with low privileges, to trigger these vulnerable operations.

Key Concerns

  • SQL queries without prepared statements
  • Unescaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Ozh' Avatar Popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ozh' Avatar Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

0% escaped1 total outputs
Attack Surface

Ozh' Avatar Popup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterthe_contentwp_ozh_avatarpopup.php:170
filterthe_excerpt_rsswp_ozh_avatarpopup.php:171
filterwp_headwp_ozh_avatarpopup.php:172
Maintenance & Trust

Ozh' Avatar Popup Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedSep 18, 2010
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Ozh' Avatar Popup Developer Profile

Ozh

27 plugins · 5K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ozh' Avatar Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
avatarpop
Data Attributes
data-gravatar_iddata-defaultdata-size
Shortcode Output
<span class="avatarpop"><a href="mailto:<img src="http://www.gravatar.com/avatar.php?
FAQ

Frequently Asked Questions about Ozh' Avatar Popup