PDF Rack – PDF Viewer, Document Manager & Embed PDF Files Security & Risk Analysis

wordpress.org/plugins/pdf-rack

The all-in-one PDF manager for WordPress — upload, organize, and embed PDF documents with a beautiful responsive viewer. Works with Gutenberg, Element …

0 active installs v1.0.3 PHP 7.4+ WP 5.8+ Updated Feb 26, 2026
document-viewerembed-pdfgutenberg-pdfpdf-managerpdf-viewer
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is PDF Rack – PDF Viewer, Document Manager & Embed PDF Files Safe to Use in 2026?

Generally Safe

Score 100/100

PDF Rack – PDF Viewer, Document Manager & Embed PDF Files has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "pdf-rack" plugin v1.0.4 demonstrates a strong security posture based on the provided static analysis. The absence of any identified attack surface (AJAX handlers, REST API routes, shortcodes, cron events) is a significant positive, as it minimizes potential entry points for attackers. Furthermore, the code adheres to secure coding practices, with all SQL queries using prepared statements and all output being properly escaped. The plugin also avoids dangerous functions, file operations, and external HTTP requests, all of which are excellent indicators of a well-developed and secure plugin.

While the static analysis reveals no immediate vulnerabilities, the complete lack of taint analysis flows (0 total analyzed) is a point of concern. This could indicate that the analysis tool was unable to effectively trace data flows within the plugin, or that the plugin's structure is too simplistic to trigger such analyses. The absence of recorded vulnerabilities in its history is a positive, suggesting a history of stability and security. However, this must be considered in conjunction with the limited taint analysis.

In conclusion, "pdf-rack" v1.0.4 appears to be a secure plugin with strong adherence to secure coding best practices. Its minimal attack surface and proper handling of data are commendable. The only significant area for potential concern is the lack of comprehensive taint analysis, which might leave some subtle vulnerabilities undetected. The absence of any historical vulnerabilities is a strong positive, reinforcing its apparent security. This plugin can be considered low risk, with the caveat of limited dynamic analysis data.

Key Concerns

  • No taint analysis data provided
Vulnerabilities
None known

PDF Rack – PDF Viewer, Document Manager & Embed PDF Files Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

PDF Rack – PDF Viewer, Document Manager & Embed PDF Files Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

100% escaped14 total outputs
Attack Surface

PDF Rack – PDF Viewer, Document Manager & Embed PDF Files Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuincludes\Admin\Admin.php:41
actionadmin_enqueue_scriptsincludes\Admin\Admin.php:42
filterscript_loader_tagincludes\Admin\Admin.php:43
filterparent_fileincludes\Admin\Admin.php:44
filterwp_prepare_attachment_for_jsincludes\Admin\Admin.php:47
actionadmin_initincludes\Admin\Admin.php:49
actioninitincludes\Blocks\PdfRackBlock.php:22
actionrest_api_initincludes\Core\Controller.php:34
actioninitincludes\Core\Taxonomy.php:22
actioninitincludes\Frontend\Frontend.php:25
filterscript_loader_tagincludes\Frontend\Frontend.php:26
actionplugins_loadedpdf-rack.php:121
Maintenance & Trust

PDF Rack – PDF Viewer, Document Manager & Embed PDF Files Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.4
Downloads256

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PDF Rack – PDF Viewer, Document Manager & Embed PDF Files Developer Profile

codersuraz

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PDF Rack – PDF Viewer, Document Manager & Embed PDF Files

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pdf-rack/assets/admin/css/main.css/wp-content/plugins/pdf-rack/assets/admin/js/main.js
Script Paths
/wp-content/plugins/pdf-rack/assets/admin/js/main.js
Version Parameters
pdf-rack/assets/admin/js/main.js?t=pdf-rack/assets/admin/css/main.css?t=

HTML / DOM Fingerprints

CSS Classes
pdfrack-containerpdfrack-admin-app
Data Attributes
data-pdfrack-pdf-urldata-pdfrack-assets-url
JS Globals
pdfRack
REST Endpoints
/wp-json/pdf-rack/v1/
FAQ

Frequently Asked Questions about PDF Rack – PDF Viewer, Document Manager & Embed PDF Files