
Personalised Gift Supply – Listing Tool Security & Risk Analysis
wordpress.org/plugins/personalised-gift-supply-listing-toolHere is a short description of the plugin. This should be no more than 150 characters. No markup here.
Is Personalised Gift Supply – Listing Tool Safe to Use in 2026?
Generally Safe
Score 92/100Personalised Gift Supply – Listing Tool has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "personalised-gift-supply-listing-tool" plugin version 1.0.6 presents a mixed security posture. While the vast majority of its output is properly escaped and it boasts a clean vulnerability history with no known CVEs, there are significant concerns regarding its attack surface and data handling. The presence of three REST API routes without permission callbacks is a critical flaw, potentially allowing unauthorized access and manipulation of plugin functionality. Additionally, the analysis indicates three flows with unsanitized paths, although these did not reach a critical or high severity in the static analysis, they still represent potential entry points for vulnerabilities if not handled with extreme care. The complete lack of capability checks and the reliance on nonce checks alone for some entry points are also weaknesses that increase the risk profile.
Key Concerns
- REST API routes without permission callbacks
- Flows with unsanitized paths
- No capability checks
- SQL queries without prepared statements
- AJAX handlers without auth checks
Personalised Gift Supply – Listing Tool Security Vulnerabilities
Personalised Gift Supply – Listing Tool Release Timeline
Personalised Gift Supply – Listing Tool Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Personalised Gift Supply – Listing Tool Attack Surface
AJAX Handlers 6
REST API Routes 3
WordPress Hooks 30
Maintenance & Trust
Personalised Gift Supply – Listing Tool Maintenance & Trust
Maintenance Signals
Community Trust
Personalised Gift Supply – Listing Tool Alternatives
No alternatives data available yet.
Personalised Gift Supply – Listing Tool Developer Profile
1 plugin · 0 total installs
How We Detect Personalised Gift Supply – Listing Tool
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/personalised-gift-supply-listing-tool/assets/css/style.css/wp-content/plugins/personalised-gift-supply-listing-tool/assets/js/script.js/wp-content/plugins/personalised-gift-supply-listing-tool/assets/css/jquery-ui.css/wp-content/plugins/personalised-gift-supply-listing-tool/assets/css/fronend_style.css/wp-content/plugins/personalised-gift-supply-listing-tool/assets/js/html2canvas.js/wp-content/plugins/personalised-gift-supply-listing-tool/assets/js/jquery.bpopup.min.js/wp-content/plugins/personalised-gift-supply-listing-tool/assets/js/jqueryrotate.min.js/wp-content/plugins/personalised-gift-supply-listing-tool/assets/js/frontend_script.jsassets/images/Personalised_Gift_Supply_Logo_WP.pngHTML / DOM Fingerprints
pgs_productscnc_b2b_image_urlcnc_b2b_ajaxcnc_b2b_fileuploaded