TechGasp Pin Master Security & Risk Analysis

wordpress.org/plugins/pinterest-master

TechGasp Pin Master adds the follow me on pinterest, pin it button, show pinterest profile and show pinterest board to your wordpress website.

300 active installs v5.1.4 PHP + WP 3.5+ Updated Mar 11, 2021
pinpin-itpinteresttechgasp
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TechGasp Pin Master Safe to Use in 2026?

Generally Safe

Score 85/100

TechGasp Pin Master has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'pinterest-master' v5.1.4 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices by using prepared statements for all SQL queries and includes a single nonce check, which are good indicators of developer awareness. The absence of known CVEs and critical or high-severity vulnerabilities in its history further contributes to a perception of relative security. Furthermore, the lack of a significant attack surface through AJAX handlers, REST API routes, shortcodes, or cron events is a notable strength, reducing potential entry points for attackers.

However, a significant concern arises from the low percentage (20%) of properly escaped output. This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities where user-supplied data could be injected into the frontend without proper sanitization. While the static analysis did not identify any direct taint flows indicating immediate exploitability, the lack of output escaping significantly broadens the potential for indirect XSS attacks. The plugin also lacks capability checks, which could allow unauthenticated or lower-privileged users to trigger unintended actions if an attack vector were to be discovered within the limited attack surface.

In conclusion, while the plugin avoids common pitfalls like unpatched vulnerabilities and raw SQL queries, the pervasive issue with output escaping presents a tangible risk. The limited attack surface and nonce check are positive, but the lack of comprehensive output sanitization and capability checks leaves room for improvement. Users should be aware of the potential for XSS vulnerabilities.

Key Concerns

  • Low output escaping percentage
  • No capability checks
Vulnerabilities
None known

TechGasp Pin Master Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TechGasp Pin Master Release Timeline

v5.1.4Current
v5.1.2
v5.1.1
v5.1.0
v5.0.15
v5.0.12
v5.0.11
v5.0.10
v5.0.9
v5.0.8
v5.0.6
v5.0.5
v5.0.4
v5.0
v4.4.5
v4.4.4
v4.4.3
v4.4.2.6
v4.4.2.5
v4.4.2.4
Code Analysis
Analyzed Mar 16, 2026

TechGasp Pin Master Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
96
24 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped120 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
display (includes\pinterest-master-admin-settings-wide-table-options.php:10)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

TechGasp Pin Master Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_menuincludes\pinterest-master-admin-addons.php:39
actionadmin_menuincludes\pinterest-master-admin-addons.php:42
actionadmin_menuincludes\pinterest-master-admin-settings-wide.php:50
actionadmin_menuincludes\pinterest-master-admin-settings-wide.php:53
actionnetwork_admin_menuincludes\pinterest-master-admin.php:10
actionadmin_menuincludes\pinterest-master-admin.php:11
actionadmin_menuincludes\pinterest-master-admin.php:14
actionwp_footerincludes\pinterest-master-settings-wide.php:75
actionwidgets_initincludes\pinterest-master-widget-buttons.php:3
filterthe_contentpinterest-master.php:52
filterplugin_action_linkspinterest-master.php:53
Maintenance & Trust

TechGasp Pin Master Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 11, 2021
PHP min version
Downloads77K

Community Trust

Rating74/100
Number of ratings18
Active installs300
Developer Profile

TechGasp Pin Master Developer Profile

TechGasp

20 plugins · 3K total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TechGasp Pin Master

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/pinterest-master/js/pinterest-master.min.js/wp-content/plugins/pinterest-master/js/pinterest-master.js
Version Parameters
pinterest-master/js/pinterest-master.min.js?ver=pinterest-master/js/pinterest-master.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- TechGasp Pin Master Add Content With Quote --><!-- TechGasp Pinterest Master Follow Me On Pinterest Link --><!-- TechGasp Pinterest Master Pin It Button --><!-- TechGasp Pinterest Master Show Pinterest Profile -->+1 more
Data Attributes
data-pin-hoverdata-pin-rounddata-pin-savedata-pin-tall
FAQ

Frequently Asked Questions about TechGasp Pin Master