
Plugin Information Card Security & Risk Analysis
wordpress.org/plugins/plugin-information-cardThis plugin adds the functionality to output information about plugins in the WordPress plugin directory.
Is Plugin Information Card Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Information Card has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "plugin-information-card" v1.0.1 exhibits a strong security posture based on the provided static analysis. It effectively utilizes prepared statements for all SQL queries and has no recorded vulnerabilities or CVEs, indicating a mature development and maintenance process. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure profile. However, a notable weakness is the complete lack of nonce checks and capability checks across its identified entry points, which is a significant concern for security. While the plugin has only one entry point (a shortcode) and no unprotected AJAX handlers or REST API routes, the absence of these fundamental security measures means that any interaction with the shortcode could potentially be exploited without proper user authentication or authorization verification. While the output escaping is partially implemented, it's not fully comprehensive, leaving a small window for potential cross-site scripting (XSS) vulnerabilities if user-controlled data is ever rendered.
Key Concerns
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
- Partial output escaping
Plugin Information Card Security Vulnerabilities
Plugin Information Card Code Analysis
Output Escaping
Plugin Information Card Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Plugin Information Card Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Information Card Alternatives
WP Social Integration
wp-social-integration
WP social integration brings login by facebook, adds basic & opengraph metadata, facebook social plugins anywhere in page
Sticky Video for Youtube
yt-sticky-video
Gutenberg block to adjust sticky video on frontend side.
Codecorun – Other Installation Details
codecorun-other-installation-details
A simple plugin that will display other information to your installed plugins.
XpressPay Payment Gateway
xpresspay-payment-gateway
XpressPay Payment Gateway allows you to accept online payments on your Woocommerce store via Visa Cards, Mastercards, Verve Cards, Bank Transfer, USSD …
WooPayments: Integrated WooCommerce Payments
woocommerce-payments
Securely accept credit and debit cards on your WooCommerce store. Manage payments without leaving your WordPress dashboard. Only with WooPayments.
Plugin Information Card Developer Profile
12 plugins · 43K total installs
How We Detect Plugin Information Card
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
plugin-cardplugin-card-topcolumn-nameplugin-iconplugin-card-bottomcolumn-ratingstar-ratingstar+6 moredata-slug<div class="plugin-card plugin-card-%slug%"><div class="plugin-card-top"><div class="name column-name"><h3><a href="%plugin_link%">%name%<img src="%icon%" class="plugin-icon" alt="%name%"></a></h3></div><div class="desc column-description">%short_description%<p class="authors"><cite><div class="plugin-card-bottom"><div class="vers column-rating"><div class="star-rating"></div><span class="num-ratings" aria-hidden="true">(%num_ratings%)</span></div><div class="column-updated"></div><div class="column-downloaded">