
Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/portfolioCreate and add personal portfolio to your WordPress website. Manage and showcase past projects to get more clients.
Is Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress Safe to Use in 2026?
Mostly Safe
Score 77/100Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The "portfolio" v2.58 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by implementing robust nonce and capability checks, with a high percentage of properly escaped output and SQL queries utilizing prepared statements. The static analysis shows a relatively small attack surface, and importantly, no unprotected entry points were identified. However, the presence of a single "unserialize" function in the code raises a significant concern, as this function is notorious for its potential to lead to remote code execution vulnerabilities if not handled with extreme caution and sanitization. Furthermore, the taint analysis revealed one flow with an unsanitized path, indicating a potential weakness where user-supplied data could be manipulated. The vulnerability history, while not currently showing critical or high severity issues, indicates a pattern of medium severity vulnerabilities, specifically Cross-Site Scripting (XSS) issues, with one such vulnerability remaining unpatched. This historical trend, coupled with the static analysis findings, suggests that while the plugin has areas of strength, there are critical areas that require immediate attention and diligent security practices.
Key Concerns
- Unpatched CVE (Medium Severity)
- Dangerous function detected (unserialize)
- Taint flow with unsanitized path
- SQL queries not using prepared statements (57% prepared)
Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Portfolio <= 2.58 - Authenticated (Author+) Stored Cross-Site Scripting
Portfolio by BestWebSoft < 2.4.0 - Reflected Cross-Site Scripting
Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 38
Maintenance & Trust
Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress Alternatives
Radius Portfolio – Filterable Grid, Gallery & Slider Portfolio
tlp-portfolio
A simple and powerful WordPress portfolio plugin to showcase your creative work beautifully with different ways.
Portfolio, Gallery, Product Catalog – Grid KIT Portfolio
portfolio-wp
Portfolio, gallery, product catalog, teams, logos and more. All-in-one - Grid Kit Portfolio Gallery plugin!
Filterable Portfolio
filterable-portfolio
A WordPress Portfolio plugin to display portfolio/project images to your site.
Responsive Filterable Portfolio
responsive-filterable-portfolio
This is a beautiful responsive portfolio with responsive lightbox plugin for WordPress blogs and sites. Admin can manage any number of videos, images, …
Advance Portfolio Grid, Slider and Gallery – Showcase Projects, Images and Videos
advance-portfolio-grid
Create responsive and customizable portfolio grids to showcase projects, case studies, and creative work on your WordPress site.
Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress Developer Profile
32 plugins · 17K total installs
How We Detect Portfolio by BestWebSoft – Work and Projects Presentation Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/portfolio/css/frontend.css/wp-content/plugins/portfolio/css/magnific-popup.css/wp-content/plugins/portfolio/js/jquery.magnific-popup.min.js/wp-content/plugins/portfolio/js/main.js/wp-content/plugins/portfolio/js/main.js/wp-content/plugins/portfolio/js/jquery.magnific-popup.min.jsportfolio/css/frontend.css?ver=portfolio/css/magnific-popup.css?ver=portfolio/js/jquery.magnific-popup.min.js?ver=portfolio/js/main.js?ver=HTML / DOM Fingerprints
portfolio_wrapportfolio_imageportfolio_title<!-- Portfolio by BestWebSoft --><!-- Start Portfolio --><!-- End Portfolio --><!-- Portfolio Item -->+1 moredata-portfolio-iddata-item-idprtfl_frontend_options[portfolio][portfolio id=""]