Light Blue API for ProPhoto Plug-in Security & Risk Analysis

wordpress.org/plugins/prophoto-light-blue-api-add-on

Send information directly from your ProPhoto 5 contact form to your Light Blue account.

10 active installs v1.0.9 PHP + WP 3.5+ Updated Mar 11, 2019
business-managementlight-bluephotographypro-photoprophoto
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Light Blue API for ProPhoto Plug-in Safe to Use in 2026?

Generally Safe

Score 85/100

Light Blue API for ProPhoto Plug-in has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "prophoto-light-blue-api-add-on" plugin v1.0.9 exhibits a generally strong security posture based on the static analysis provided. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with exposed entry points is a significant strength, drastically reducing the potential attack surface. Furthermore, the code demonstrates good practices by exclusively using prepared statements for SQL queries and having no recorded vulnerabilities, including CVEs.

However, a notable concern arises from the output escaping. With 18% properly escaped outputs from 11 total outputs, it indicates that a significant portion of the plugin's output is not being properly sanitized. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly included in these unescaped outputs. The presence of external HTTP requests, while not inherently a vulnerability, warrants attention to ensure they are handled securely and do not expose the site to further risks.

In conclusion, the plugin has a solid foundation with its limited attack surface and secure database practices. The primary area of risk lies in the insufficient output escaping, which could be a vector for XSS attacks. The lack of historical vulnerabilities is positive but does not negate the importance of addressing the current code signals. The plugin is recommended for further scrutiny, focusing on the unescaped output and the security of its external HTTP requests.

Key Concerns

  • Low percentage of properly escaped output
  • Presence of external HTTP requests
Vulnerabilities
None known

Light Blue API for ProPhoto Plug-in Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Light Blue API for ProPhoto Plug-in Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

18% escaped11 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
lb_settings_page (prophoto-light-blue-api.php:80)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Light Blue API for ProPhoto Plug-in Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actioninitprophoto-light-blue-api.php:30
actionadmin_menuprophoto-light-blue-api.php:53
actionpp_contact_pre_emailprophoto-light-blue-api.php:56
Maintenance & Trust

Light Blue API for ProPhoto Plug-in Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 11, 2019
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Light Blue API for ProPhoto Plug-in Developer Profile

TomCatchesides

2 plugins · 110 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Light Blue API for ProPhoto Plug-in

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/prophoto-light-blue-api-add-on/style.css/wp-content/plugins/prophoto-light-blue-api-add-on/js/prophoto_lightbox_api.js
Script Paths
/wp-content/plugins/prophoto-light-blue-api-add-on/js/prophoto_lightbox_api.js
Version Parameters
prophoto-light-blue-api-add-on/style.css?ver=prophoto-light-blue-api-add-on/js/prophoto_lightbox_api.js?ver=

HTML / DOM Fingerprints

Data Attributes
pp_light_blue_mapping_field_pp_light_blue_mapping_param_pp_light_blue_api_keypp_light_blue_decimal_separatorpp_light_blue_debugpp_light_blue_submit+1 more
FAQ

Frequently Asked Questions about Light Blue API for ProPhoto Plug-in