
PRIMER by chloédigital Security & Risk Analysis
wordpress.org/plugins/primer-by-chloedigitalThe best plugin to help grow your organic traffic via product-based images. Start making your images discoverable through product searches.
Is PRIMER by chloédigital Safe to Use in 2026?
Use With Caution
Score 63/100PRIMER by chloédigital has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "primer-by-chloedigital" plugin v1.0.25 presents a significant security risk due to multiple unprotected AJAX handlers and a concerning lack of proper output escaping and input sanitization. The static analysis reveals a substantial attack surface with all three identified entry points (AJAX handlers) lacking authentication checks. Furthermore, only a small percentage of SQL queries use prepared statements, and a similarly low percentage of output is properly escaped, indicating potential for SQL injection and cross-site scripting vulnerabilities. The presence of dangerous functions like `create_function` adds to the overall insecurity. The vulnerability history, including a known medium severity Cross-site Scripting (XSS) vulnerability that is currently unpatched, reinforces these concerns. While the absence of file operations and external HTTP requests is a positive sign, the current security posture is weak, requiring immediate attention to address the identified risks.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Low percentage of prepared SQL statements
- Unpatched Medium severity CVE
- Use of dangerous function create_function
- No capability checks on entry points
- Flows with unsanitized paths
PRIMER by chloédigital Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
PRIMER by chloédigital <= 1.0.25 - Reflected Cross-Site Scripting
PRIMER by chloédigital Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
PRIMER by chloédigital Attack Surface
AJAX Handlers 3
WordPress Hooks 20
Maintenance & Trust
PRIMER by chloédigital Maintenance & Trust
Maintenance Signals
Community Trust
PRIMER by chloédigital Alternatives
hCard Widget for WordPress
hcard-widget
Creates a widget that outputs contact information for individuals or organizations with Schema.org compliant markup.
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
seo-by-rank-math
Rank Math SEO is the best WordPress SEO plugin with the features of many SEO and AI SEO tools in a single package to help multiply your SEO traffic.
SureRank SEO – Smart Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
surerank
SureRank – SEO Assistant with Meta Tags, Social Preview, XML Sitemap, and Schema
Schema – All In One Schema Rich Snippets
all-in-one-schemaorg-rich-snippets
Improve SEO, elevate rankings and Boost CTR. Supports different types of content and works well with Google, Bing, Yahoo, and Facebook.
FAQ Schema For Pages And Posts
faq-schema-for-pages-and-posts
FAQ Schema For Pages And Posts by Krystian Szastok Founder of RobotZebra - a London based SEO agency, allows you to turn questions and answers on your …
PRIMER by chloédigital Developer Profile
1 plugin · 60 total installs
How We Detect PRIMER by chloédigital
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/primer-by-chloedigital/admin/css/primer-by-chloedigital-admin.css/wp-content/plugins/primer-by-chloedigital/admin/js/primer-by-chloedigital-admin.js/wp-content/plugins/primer-by-chloedigital/admin/js/admin-scripts.js/wp-content/plugins/primer-by-chloedigital/admin/js/jquery.validate.min.jsadmin/js/primer-by-chloedigital-admin.jsadmin/js/admin-scripts.jsadmin/js/jquery.validate.min.jsprimer-by-chloedigital/admin/css/primer-by-chloedigital-admin.css?ver=primer-by-chloedigital/admin/js/primer-by-chloedigital-admin.js?ver=primer-by-chloedigital/admin/js/jquery.validate.min.js?ver=HTML / DOM Fingerprints
primer-settings-messageprimer_check_settings_messageprimer_message_submark_containerprimer_message_submarkdashicons-primer-mark-whtPBCD_PLUGIN_VERSION