
Behance Portfolio Manager Security & Risk Analysis
wordpress.org/plugins/portfolio-manager-powered-by-behanceShow Behance Projects to Your WordPress Website
Is Behance Portfolio Manager Safe to Use in 2026?
High Risk
Score 42/100Behance Portfolio Manager carries significant security risk with 6 known CVEs, 6 still unpatched. Consider switching to a maintained alternative.
The "portfolio-manager-powered-by-behance" v1.8.0 plugin exhibits a concerning security posture despite some positive indicators. While it shows good practices in areas like SQL query preparation (76%) and output escaping (89%), the presence of two AJAX handlers without authentication checks is a significant risk. This directly creates an attack surface that could be exploited by unauthenticated users.
The taint analysis reveals a high number of flows with unsanitized paths (10 out of 14), with all 10 classified as high severity. This strongly suggests a propensity for sensitive data to be improperly handled, potentially leading to various injection vulnerabilities if not mitigated at the endpoint. The vulnerability history further exacerbates these concerns, with 6 known CVEs, all of which are currently unpatched. The types of past vulnerabilities, including CSRF, XSS, missing authorization, and SQL injection, align with the potential risks identified in the taint analysis and the unprotected AJAX handlers, indicating a pattern of recurring security weaknesses.
In conclusion, while the plugin demonstrates some diligent coding practices in specific areas, the combination of unprotected entry points, critical taint flows, and a history of unpatched vulnerabilities, particularly those related to input validation and authorization, presents a substantial security risk. The plugin requires immediate attention to address the identified vulnerabilities and to implement robust authorization and sanitization checks for all entry points.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- 6 unpatched CVEs
- Bundled outdated library (TinyMCE v1.0)
Behance Portfolio Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Behance Portfolio Manager <= 1.7.5 - Cross-Site Request Forgery
Behance Portfolio Manager <= 1.7.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Behance Portfolio Manager <= 1.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Behance Portfolio Manager <= 1.7.4 - Missing Authorization
Behance Portfolio Manager <= 1.7.4 - Authenticated (Administrator+) SQL Injection
Behance Portfolio Manager <= 1.7.4 - Authenticated (Contributor+) SQL Injection
Behance Portfolio Manager Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Behance Portfolio Manager Attack Surface
AJAX Handlers 4
Shortcodes 4
WordPress Hooks 26
Maintenance & Trust
Behance Portfolio Manager Maintenance & Trust
Maintenance Signals
Community Trust
Behance Portfolio Manager Alternatives
GS Behance Portfolio – Display Projects, Gallery & Slider
gs-behance-portfolio
Showcase Behance projects on your site with GS Behance Portfolio. Display in Grid, Slider, Gallery & more responsive layouts.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Visual Portfolio, Photo Gallery & Post Grid
visual-portfolio
Modern photo gallery and portfolio plugin with advanced layouts editor. Clean gallery styles with powerful settings in the Gutenberg block.
Portfolio Post Type
portfolio-post-type
This plugin registers a custom post type for portfolio items. It also registers separate portfolio taxonomies for tags and categories.
Premium Portfolio Features for Phlox theme
auxin-portfolio
Showcase your projects beautifully in Phlox theme
Behance Portfolio Manager Developer Profile
3 plugins · 30K total installs
How We Detect Behance Portfolio Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/portfolio-manager-powered-by-behance/css/project_view.css/wp-content/plugins/portfolio-manager-powered-by-behance/css/project_view_responsive.css/wp-content/plugins/portfolio-manager-powered-by-behance/css/bootstrap.min.css/wp-content/plugins/portfolio-manager-powered-by-behance/css/font-awesome.min.css/wp-content/plugins/portfolio-manager-powered-by-behance/js/plugins.js/wp-content/plugins/portfolio-manager-powered-by-behance/js/custom.js/wp-content/plugins/portfolio-manager-powered-by-behance/js/bootstrap.min.js/wp-content/plugins/portfolio-manager-powered-by-behance/js/plugins.js/wp-content/plugins/portfolio-manager-powered-by-behance/js/custom.js/wp-content/plugins/portfolio-manager-powered-by-behance/js/bootstrap.min.jsportfolio-manager-powered-by-behance/css/project_view.css?ver=portfolio-manager-powered-by-behance/css/project_view_responsive.css?ver=portfolio-manager-powered-by-behance/css/bootstrap.min.css?ver=portfolio-manager-powered-by-behance/css/font-awesome.min.css?ver=portfolio-manager-powered-by-behance/js/plugins.js?ver=portfolio-manager-powered-by-behance/js/custom.js?ver=portfolio-manager-powered-by-behance/js/bootstrap.min.js?ver=HTML / DOM Fingerprints
eds-bpm-project-itemeds-bpm-project-metaeds-bpm-project-titleeds-bpm-project-descriptioneds-bpm-project-likeseds-bpm-project-viewseds-bpm-project-commentseds-bpm-project-createddata-behance-api-keydata-behance-usernamedata-behance-project-iddata-behance-project-titledata-behance-project-descriptiondata-behance-project-url+5 moreEDS_BPM_AJAX_URLEDS_BPM_DATA[edsbportman][edsbportmansp][edsbportmansc][edsbportmanmc]