Prosperity Security & Risk Analysis

wordpress.org/plugins/prosperity

Displays random scriptures in posts and admin panel. Bible verses about prosperity. Prosperity Scriptures.

10 active installs v2.1.0 PHP + WP 5.0+ Updated Mar 10, 2021
biblebible-versesbible-verses-about-prosperityprosperitywealth
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Prosperity Safe to Use in 2026?

Generally Safe

Score 85/100

Prosperity has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "prosperity" v2.1.0 plugin exhibits a generally strong security posture with no recorded vulnerabilities and a limited attack surface. The absence of dangerous functions, file operations, external HTTP requests, and SQL queries indicates a conscious effort to avoid common security pitfalls. Furthermore, the fact that all SQL queries use prepared statements is a significant strength. However, the static analysis reveals some areas for improvement. A concerning finding is the low percentage of properly escaped output, suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of a shortcode that could serve as an entry point for unsanitized user input. The lack of nonce and capability checks, while seemingly mitigated by the zero unprotected entry points, still represents a potential weakness if the logic protecting those entry points were to be bypassed or misconfigured.

While the plugin has no known CVEs and a clean vulnerability history, this doesn't guarantee future security. The current analysis highlights a need to address output escaping thoroughly. The presence of a shortcode without explicit capability checks, even with a seemingly zero unprotected entry point, warrants careful review of how that shortcode's output is handled to ensure it's completely sanitized and incapable of rendering malicious scripts. In conclusion, "prosperity" v2.1.0 is built on good foundational security practices, but the output escaping and the potential implications of the shortcode without explicit authorization checks present moderate risks that should be addressed to further harden the plugin.

Key Concerns

  • Low percentage of properly escaped output
  • Shortcode present without explicit capability checks
  • No nonce checks
Vulnerabilities
None known

Prosperity Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Prosperity Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

9% escaped11 total outputs
Attack Surface

Prosperity Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[Prosperity] prosperity.php:20
WordPress Hooks 5
actionwidgets_initprosperity.php:21
actionadmin_noticesprosperity.php:24
actionadmin_headprosperity.php:25
actionadmin_menuprosperity.php:26
filterplugin_row_metaprosperity.php:27
Maintenance & Trust

Prosperity Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 10, 2021
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Prosperity Developer Profile

hahncgdev

2 plugins · 110 total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
2724 days
View full developer profile
Detection Fingerprints

How We Detect Prosperity

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
prosper
Shortcode Output
[Prosperity]
FAQ

Frequently Asked Questions about Prosperity