Periscope – Custom Dashboard News Widget Security & Risk Analysis

wordpress.org/plugins/periscopio

Replace the default WordPress News widget with your own customizable RSS feeds and events.

20 active installs v1.0.2 PHP 7.4+ WP 5.0+ Updated Apr 8, 2026
dashboardfeedsnewsrsswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Periscope – Custom Dashboard News Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Periscope – Custom Dashboard News Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The Periscopio plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. A significant strength is the complete absence of SQL injection vulnerabilities due to 100% prepared statement usage and the lack of any observed dangerous functions or file operations. The plugin also demonstrates good practices in output escaping, with 96% of outputs properly sanitized, minimizing the risk of cross-site scripting (XSS) vulnerabilities. Furthermore, the presence of nonce and capability checks on all identified AJAX entry points indicates a conscious effort to prevent unauthorized actions.

Despite these strengths, there are minor areas that warrant attention. The plugin makes two external HTTP requests, which, while not inherently a vulnerability, introduce a potential dependency on external services and could be a vector for man-in-the-middle attacks if not handled securely (e.g., with proper SSL verification, which is not detailed here). The attack surface is small with only 3 AJAX handlers, and reassuringly, all have authentication checks. The complete lack of recorded vulnerabilities in its history is a positive sign, suggesting a well-maintained and secure codebase to date. Overall, Periscopio v1.0.0 appears to be a secure plugin, with its main potential for improvement lying in the robust handling of its external HTTP requests.

Key Concerns

  • External HTTP requests (potential dependency risk)
Vulnerabilities
None known

Periscope – Custom Dashboard News Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Periscope – Custom Dashboard News Widget Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Periscope – Custom Dashboard News Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
107 escaped
Nonce Checks
3
Capability Checks
5
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

96% escaped111 total outputs
Attack Surface

Periscope – Custom Dashboard News Widget Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_periscopio_update_locationincludes\class-dashboard-widget.php:24
authwp_ajax_periscopio_validate_feedincludes\functions.php:176
authwp_ajax_periscopio_refresh_widgetincludes\functions.php:189
WordPress Hooks 7
actionwp_dashboard_setupincludes\class-dashboard-widget.php:23
actionadmin_menuincludes\class-settings-page.php:23
actionadmin_initincludes\class-settings-page.php:24
actionadmin_noticesincludes\class-settings-page.php:25
actionplugins_loadedperiscopio.php:141
actionadmin_enqueue_scriptsperiscopio.php:202
actionadmin_noticesperiscopio.php:237
Maintenance & Trust

Periscope – Custom Dashboard News Widget Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 8, 2026
PHP min version7.4
Downloads376

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Periscope – Custom Dashboard News Widget Developer Profile

Fernando Tellado

21 plugins · 25K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Periscope – Custom Dashboard News Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/periscopio/assets/css/admin.css/wp-content/plugins/periscopio/assets/js/admin.js
Script Paths
/wp-content/plugins/periscopio/assets/js/admin.js
Version Parameters
periscopio/assets/css/admin.css?ver=periscopio/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
periscopio-settings-pageperiscopio-widget-title
Data Attributes
data-periscopio-action
JS Globals
periscopioAdmin
FAQ

Frequently Asked Questions about Periscope – Custom Dashboard News Widget