Projects by Serge Liatko Security & Risk Analysis

wordpress.org/plugins/projects-by-serge-liatko

Easy way to publish and organize your portfolio online. Show off what you have done and your current projects. Easy to use, light and flexible.

10 active installs v0.5 PHP + WP 3.7+ Updated Oct 17, 2016
artcreativeportfolioprojectprojects
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Projects by Serge Liatko Safe to Use in 2026?

Generally Safe

Score 85/100

Projects by Serge Liatko has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The static analysis of the "projects-by-serge-liatko" plugin v0.5 reveals a strong security posture in several key areas. The absence of any detected dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly commendable. Furthermore, the high percentage of properly escaped output (92%) and the presence of a nonce check indicate good development practices aimed at preventing common web vulnerabilities.

The plugin's attack surface also appears minimal, with zero AJAX handlers, REST API routes, shortcodes, and cron events identified. The taint analysis found no flows with unsanitized paths, suggesting that user-supplied data is not being mishandled in critical ways. The plugin's vulnerability history is also entirely clear, with no recorded CVEs, which is a positive indicator of its current security.

While the plugin demonstrates excellent security fundamentals, the lack of any capability checks on its entry points, combined with the absence of any identified unprotected entry points, might suggest a very limited functionality or that it relies entirely on WordPress's default security for any interactions. This is not inherently a weakness, but it means the plugin itself doesn't explicitly enforce granular permissions. Overall, the plugin appears very secure based on the provided data, with strengths in preventing direct code execution, SQL injection, and XSS, and no known vulnerabilities.

Vulnerabilities
None known

Projects by Serge Liatko Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Projects by Serge Liatko Release Timeline

v0.5Current
v0.4
v0.3
v0.2
v0.1.1
v0.1
Code Analysis
Analyzed Apr 16, 2026

Projects by Serge Liatko Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
24 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped26 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_project_meta (admin/class-projects-plugin-admin.php:49)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Projects by Serge Liatko Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
actionadmin_menuadmin/class-projects-plugin-admin.php:24
actionadmin_initadmin/class-projects-plugin-admin.php:26
filtermanage_project_posts_columnsadmin/class-projects-plugin-admin.php:29
filtermanage_project_posts_custom_columnadmin/class-projects-plugin-admin.php:30
actionload-edit.phpadmin/class-projects-plugin-admin.php:32
actionload-post.phpadmin/class-projects-plugin-admin.php:34
actionload-post-new.phpadmin/class-projects-plugin-admin.php:35
actionedit_form_after_editoradmin/class-projects-plugin-admin.php:38
actionadd_meta_boxes_projectadmin/class-projects-plugin-admin.php:40
actionsave_postadmin/class-projects-plugin-admin.php:42
actionadmin_enqueue_scriptsadmin/class-projects-plugin-admin.php:343
actionadmin_enqueue_scriptsadmin/class-projects-plugin-admin.php:348
actionadmin_enqueue_scriptsadmin/class-projects-plugin-admin.php:354
actioninitprojects-by-serge-liatko.php:50
actioninitprojects-by-serge-liatko.php:53
actionpre_get_postsprojects-by-serge-liatko.php:54
actiontemplate_redirectprojects-by-serge-liatko.php:55
filterplugin_action_linksprojects-by-serge-liatko.php:61
filterplugin_row_metaprojects-by-serge-liatko.php:63
actionwp_enqueue_scriptsprojects-by-serge-liatko.php:75
filterthe_contentprojects-by-serge-liatko.php:80
filterthe_contentprojects-by-serge-liatko.php:85
filterthe_contentprojects-by-serge-liatko.php:90
filterthe_contentprojects-by-serge-liatko.php:95
actionpre_get_postsprojects-by-serge-liatko.php:100
actionwidgets_initprojects-by-serge-liatko.php:106
actionplugins_loadedprojects-by-serge-liatko.php:550
Maintenance & Trust

Projects by Serge Liatko Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 17, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Projects by Serge Liatko Developer Profile

Serge Liatko

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Projects by Serge Liatko

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/projects-by-serge-liatko/css/projects.css/wp-content/plugins/projects-by-serge-liatko/js/projects.js
Script Paths
/wp-content/plugins/projects-by-serge-liatko/js/projects.js
Version Parameters
/wp-content/plugins/projects-by-serge-liatko/css/projects.css?ver=/wp-content/plugins/projects-by-serge-liatko/js/projects.js?ver=

HTML / DOM Fingerprints

CSS Classes
after-project-widget-areacontent-widget-areawidget-areaterm-linksterm-links-taxonomy
HTML Comments
prevent direct loading define paths start plugin class declare variables +26 more
Data Attributes
data-prjcts_iddata-prjcts_post_iddata-prjcts_term_id
JS Globals
projects_pluginprjcts_show_project_linksprjcts_show_archive_linksprjcts_no_summaryprjcts_hide_widgetareaprjcts_archive_links+9 more
FAQ

Frequently Asked Questions about Projects by Serge Liatko