
Plot.wp Security & Risk Analysis
wordpress.org/plugins/plotwpAdd JSON-based plots to posts and pages using the plotly.js API
Is Plot.wp Safe to Use in 2026?
Generally Safe
Score 85/100Plot.wp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plotwp plugin, at version 0.4, presents a generally strong security posture based on the provided static analysis. There are no detected dangerous functions, all SQL queries use prepared statements, and all output is properly escaped. Furthermore, the absence of file operations, external HTTP requests, and critical or high-severity taint flows indicates a well-contained and handled codebase in these areas. The plugin also boasts no known CVEs, historical or current, suggesting a mature and secure development history. However, the lack of any nonce checks or capability checks across its entry points (two shortcodes) is a notable concern. While the attack surface is currently small and reported as unprotected entry points is zero, this can become a significant weakness if the shortcode functionality ever evolves to handle sensitive data or actions. The absence of any taint analysis flows could also be a consequence of the limited scope of the analysis or simply due to the plugin's simplicity; it doesn't necessarily confirm the complete absence of such issues in more complex scenarios.
In conclusion, plotwp v0.4 demonstrates good development practices regarding data handling and output sanitization, and its vulnerability history is excellent. The primary area of concern lies in the potential for unauthorized execution of its shortcode functionality due to the absence of security checks. While currently low risk given the limited entry points and lack of reported issues, this is a weakness that should be addressed if the plugin's features expand. The plugin is otherwise robust and appears to be developed with security in mind.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
Plot.wp Security Vulnerabilities
Plot.wp Code Analysis
Output Escaping
Plot.wp Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
Plot.wp Maintenance & Trust
Maintenance Signals
Community Trust
Plot.wp Alternatives
Visualizer: Tables and Charts Manager for WordPress
visualizer
A simple yet powerful WordPress chart plugin to effortlessly create and embed responsive charts & tables into your site, supporting multiple data …
Graphina – Charts and Graphs For Elementor
graphina-elementor-charts-and-graphs
Most Powerful Data visualization plugin for WordPress Elementor. The easiest way to build gorgeous Charts & Graphs on your Elementor website.
Chartify – WordPress Chart Plugin
chart-builder
Chartify is a powerful WordPress Chart Builder Plugin that will help you to create WordPress Graphs & Charts easily and quickly.
M Chart
m-chart
Manage data sets and display them as charts in WordPress.
iChart – Easy Charts and Graphs
ichart
Create Responsive Charts and graphs iChart! COVID-19 widget for Live Data. Sidebar ticker Widget for CORONA stats. Add beautiful graphs & charts t …
Plot.wp Developer Profile
1 plugin · 20 total installs
How We Detect Plot.wp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plotwp/defaultplot.css/wp-content/plugins/plotwp/plotly-1.19.2.min.jsHTML / DOM Fingerprints
Plotly<div id="plotwp_plotly_Plotly.plot( document.getElementById("