PDF Flip Book by Kenrys Security & Risk Analysis

wordpress.org/plugins/pdf-flip-book-by-kenrys

Simply Add PDF to your pages or post via shortcode or via WP Bakery Visual composer Element in a Flip Book Style.

20 active installs v1.1.2 PHP 5.2.4+ WP 4.6+ Updated May 21, 2018
flipbookpdfshortcodevisual-composer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is PDF Flip Book by Kenrys Safe to Use in 2026?

Generally Safe

Score 85/100

PDF Flip Book by Kenrys has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "pdf-flip-book-by-kenrys" plugin v1.1.2 presents a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and utilizes prepared statements for all its SQL queries, which are good practices. It also has a minimal attack surface, with no AJAX handlers or REST API routes directly exposed without authentication. However, significant concerns arise from the static analysis. A critical finding is that 100% of its output is unescaped, meaning user-supplied data displayed on the frontend is vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the taint analysis revealed a flow with an unsanitized path, indicating a potential for arbitrary file access or manipulation if this path is controllable by an attacker. The lack of nonce checks and capability checks on entry points, while currently small, leaves them susceptible to unauthorized use if an attack vector is found.

Key Concerns

  • 100% of output unescaped
  • Taint flow with unsanitized path
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

PDF Flip Book by Kenrys Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PDF Flip Book by Kenrys Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped54 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<PDF_Flip_Book_Kenrys> (PDF_Flip_Book_Kenrys.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

PDF Flip Book by Kenrys Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[pfbk_pdf_flipbook] PDF_Flip_Book_Kenrys.php:70
[v_pfbk_flip_book] PDF_Flip_Book_Kenrys.php:176
WordPress Hooks 3
actionadmin_menuPDF_Flip_Book_Kenrys.php:16
actioninitPDF_Flip_Book_Kenrys.php:74
actionvc_before_initPDF_Flip_Book_Kenrys.php:142
Maintenance & Trust

PDF Flip Book by Kenrys Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 21, 2018
PHP min version5.2.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

PDF Flip Book by Kenrys Developer Profile

Kenrys

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PDF Flip Book by Kenrys

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pdf-flip-book-by-kenrys/js/pdf.js
Script Paths
js/pdf.js
Version Parameters
pdf-flip-book-by-kenrys/js/pdf.js?ver=

HTML / DOM Fingerprints

CSS Classes
PDF_Flip_Book_icon
Data Attributes
data-attachment_iddata-heightdata-widthdata-pagesdata-animation
JS Globals
PDFflipBook
Shortcode Output
[pfbk_pdf_flipbook src=width=height=pages=
FAQ

Frequently Asked Questions about PDF Flip Book by Kenrys