
Pie and Donut charts Security & Risk Analysis
wordpress.org/plugins/pie-and-donut-chartMake interactive pie charts using chart.js library using:
Is Pie and Donut charts Safe to Use in 2026?
Generally Safe
Score 85/100Pie and Donut charts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pie-and-donut-chart" plugin v1.0.0 presents a mixed security profile. On the positive side, the plugin exhibits no known vulnerabilities in its history, and the static analysis shows no dangerous functions, no file operations, no external HTTP requests, and all SQL queries are properly prepared. This suggests a generally cautious approach to core security practices. However, a significant concern arises from the complete lack of output escaping. With 10 total outputs and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user's browser through the plugin's output. Additionally, the absence of nonce checks and capability checks on the single shortcode entry point, while not directly indicated as exploitable by the current static analysis, represents a potential weakness in validating user intent and permissions. The lack of taint analysis results, while not a direct vulnerability, means that the potential for complex data flow vulnerabilities remains unassessed.
The plugin's clean vulnerability history is a strong indicator of good development practices in the past, but it does not negate the immediate risks identified in the code analysis. The absence of output escaping is a critical oversight that could lead to severe security breaches, particularly XSS. The lack of capability checks on the shortcode, while a single entry point, means that any user, regardless of their role, could potentially interact with and trigger the plugin's functionality. A balanced conclusion is that while the plugin is built on a solid foundation regarding database and external interactions, the lack of output sanitization is a critical flaw that needs immediate attention to mitigate XSS risks.
Key Concerns
- 0% output escaping
- No nonce checks
- No capability checks
Pie and Donut charts Security Vulnerabilities
Pie and Donut charts Code Analysis
Output Escaping
Pie and Donut charts Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Pie and Donut charts Maintenance & Trust
Maintenance Signals
Community Trust
Pie and Donut charts Alternatives
Extended widgets addon kit for Elementor
extended-widgets-addon-kit-for-elementor
Extended widgets addon kit for Elementor for creating accordion post and radial gauge. Animated gauge using gauge.js library
Charts and Graphs for Elementor
charts-and-graphs-for-elementor
Create beautiful, interactive charts with Graphs & Charts
Plugin Name: FusionCharts for WordPress
fc-wp
FusionCharts is a software service provider creating data visualization products. Its flagship product, FusionCharts Suite XT, is a comprehensive Java …
sr-piechart-wp
sr-piechirt-wp
Easily create and manage a piechart .Get a Fancy jQuery Pie Chart with a simple shortcode
Chartivio
chartivio
Professional, interactive data visualization for WordPress. Create stunning charts with a live-preview editor, CSV support, and manual data entry.
Pie and Donut charts Developer Profile
2 plugins · 20 total installs
How We Detect Pie and Donut charts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pie-and-donut-chart/lib/style.css/wp-content/plugins/pie-and-donut-chart/assets/js/chart.js/wp-content/plugins/pie-and-donut-chart/assets/js/chart.jspie-and-donut-chart/assets/js/chart.js?ver=1.0HTML / DOM Fingerprints
bgChartjQuery<div class="bg"><canvas id="