
Portfolio, Gallery, Product Catalog – Grid KIT Portfolio Security & Risk Analysis
wordpress.org/plugins/portfolio-wpPortfolio, gallery, product catalog, teams, logos and more. All-in-one - Grid Kit Portfolio Gallery plugin!
Is Portfolio, Gallery, Product Catalog – Grid KIT Portfolio Safe to Use in 2026?
Generally Safe
Score 100/100Portfolio, Gallery, Product Catalog – Grid KIT Portfolio has a strong security track record. Known vulnerabilities have been patched promptly.
The "portfolio-wp" plugin version 2.2.2 exhibits a generally good security posture with several strengths. The code analysis reveals a commendable 100% usage of prepared statements for SQL queries and a near-perfect 99% of outputs being properly escaped, significantly mitigating the risk of SQL injection and cross-site scripting (XSS) vulnerabilities originating from direct database interaction or content rendering.
However, there are notable concerns. The plugin exposes two AJAX handlers that lack authentication checks, creating a significant attack surface. While no critical or high severity taint flows were identified, the presence of unprotected entry points is a primary risk factor. The plugin has a history of one medium-severity vulnerability related to Cross-site Scripting, which, despite being patched, highlights a potential area for developer oversight. The overall risk is moderate, stemming from the unprotected AJAX handlers which could be leveraged for various attacks if not properly secured, despite the otherwise robust coding practices in other areas.
Key Concerns
- AJAX handlers without authentication checks
- History of medium severity XSS vulnerability
Portfolio, Gallery, Product Catalog – Grid KIT Portfolio Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
GridKit Portfolio <= 2.0.0 - Subscriber+ Stored Cross-Site Scripting
Portfolio, Gallery, Product Catalog – Grid KIT Portfolio Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Portfolio, Gallery, Product Catalog – Grid KIT Portfolio Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 10
Maintenance & Trust
Portfolio, Gallery, Product Catalog – Grid KIT Portfolio Maintenance & Trust
Maintenance Signals
Community Trust
Portfolio, Gallery, Product Catalog – Grid KIT Portfolio Alternatives
Radius Portfolio – Filterable Grid, Gallery & Slider Portfolio
tlp-portfolio
A simple and powerful WordPress portfolio plugin to showcase your creative work beautifully with different ways.
Photo Gallery for Images
new-photo-gallery
Display photos in responsive grid and lightbox layouts. Build image galleries, portfolios, and video galleries.
Filterable Portfolio
filterable-portfolio
A WordPress Portfolio plugin to display portfolio/project images to your site.
Responsive Filterable Portfolio
responsive-filterable-portfolio
This is a beautiful responsive portfolio with responsive lightbox plugin for WordPress blogs and sites. Admin can manage any number of videos, images, …
Advance Portfolio Grid, Slider and Gallery – Showcase Projects, Images and Videos
advance-portfolio-grid
Create responsive and customizable portfolio grids to showcase projects, case studies, and creative work on your WordPress site.
Portfolio, Gallery, Product Catalog – Grid KIT Portfolio Developer Profile
1 plugin · 6K total installs
How We Detect Portfolio, Gallery, Product Catalog – Grid KIT Portfolio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/portfolio-wp/js/crp-admin-script.js/wp-content/plugins/portfolio-wp/js/crp-front-script.js/wp-content/plugins/portfolio-wp/js/crp-tc-buttons.js/wp-content/plugins/portfolio-wp/css/crp-front-style.css/wp-content/plugins/portfolio-wp/css/crp-admin-style.css/wp-content/plugins/portfolio-wp/css/gkit-admin-editor-block.css/wp-content/plugins/portfolio-wp/js/crp-admin-script.js/wp-content/plugins/portfolio-wp/js/crp-front-script.js/wp-content/plugins/portfolio-wp/js/crp-tc-buttons.jsportfolio-wp/css/gkit-admin-editor-block.css?ver=HTML / DOM Fingerprints
crp-portfolio-wrapcrp-portfolio-gridcrp-portfolio-itemgkit-admin-editor-blockdata-crp-idcrp_obj[crp_portfolio[gkit