
PMID Citation Plus Security & Risk Analysis
wordpress.org/plugins/pmid-citation-plusThis plugin allows you to simply enter in PubMed IDs (PMIDs) and have a references list automatically built at the bottom of your post for you.
Is PMID Citation Plus Safe to Use in 2026?
Generally Safe
Score 85/100PMID Citation Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The pmid-citation-plus plugin, in version 1.0.8, exhibits a generally strong security posture based on the static analysis. It demonstrates excellent practices with zero AJAX handlers and REST API routes lacking authentication, as well as 100% of SQL queries utilizing prepared statements. The plugin also correctly implements nonce checks and capability checks, further bolstering its defenses. However, a significant concern arises from the low rate of proper output escaping (29%), which indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed on the frontend. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting a history of responsible development or simply a lack of past exploitable issues, but it does not negate the identified code signals.
While the plugin boasts zero total and unpatched CVEs, and no critical or high-severity taint flows, the output escaping deficiency presents a clear and actionable risk. The limited attack surface, with only one shortcode and no unprotected entry points, is a commendable aspect. The presence of file operations and external HTTP requests, while not inherently insecure, warrants attention if the data involved in these operations is not handled with extreme care. Overall, pmid-citation-plus v1.0.8 is well-defended against common injection and unauthorized access vulnerabilities, but the insufficient output escaping leaves it susceptible to XSS attacks, which is the primary area requiring immediate attention.
Key Concerns
- Low output escaping rate
PMID Citation Plus Security Vulnerabilities
PMID Citation Plus Code Analysis
Output Escaping
PMID Citation Plus Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
PMID Citation Plus Maintenance & Trust
Maintenance Signals
Community Trust
PMID Citation Plus Alternatives
Cite
cite
Help readers know how to cite your article correctly
KCite
kcite
A tool for producing citations and bibliographies in Wordpress posts. Developed for the Knowledgeblog project (http://knowledgeblog.org).
Simple Attribution
simple-attribution
A simple plugin to allow bloggers to add attribution to sourced posts.
Blockquote Cite
blockquote-cite
Blockquote Cite allows you to add easily cite references when using the blockquote tag.
Citation Note
citation-note
Easily add, manage, and display citations, references, and footnotes in posts, pages, or custom post types using a user-friendly editor interface.
PMID Citation Plus Developer Profile
1 plugin · 10 total installs
How We Detect PMID Citation Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pmid-citation-plus/css/pmidplus.css/wp-content/plugins/pmid-citation-plus/js/jquery-tooltip/jquery.tooltip.css/wp-content/plugins/pmid-citation-plus/js/jquery-tooltip/jquery.tooltip.js/wp-content/plugins/pmid-citation-plus/js/jquery-tooltip/jquery.tooltip.jsHTML / DOM Fingerprints
pmidcitationplus<!-- The actual fields for data entry --><!--SYNTAX: add_meta_box( $id, $title, $callback, $page, $context, $priority, $callback_args ); --><!-- Make sure save is intentional, not just autosave. --><!-- Verify this came from the our screen and with proper authorization -->+3 moreid="citid="pmidinput"name="pmidinput"id="pmidplusmeta"name="pmidplus_nonce"jQuery(document).readyjQuery("#cit<h1>References</h1><ul>