
PukiWiki for WordPress Security & Risk Analysis
wordpress.org/plugins/pukiwiki-for-wordpress'PukiWiki for WordPress' converts a html from pukiwiki text on an entry.
Is PukiWiki for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100PukiWiki for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pukiwiki-for-wordpress" plugin v0.2.3 exhibits a concerning security posture despite a lack of publicly disclosed vulnerabilities. While the static analysis reveals no direct entry points like AJAX handlers, REST API routes, or shortcodes, and SQL queries are properly prepared, several critical code signals raise significant red flags. The presence of 12 instances of the `create_function` dangerous function is a major concern, as it can lead to code injection vulnerabilities. Furthermore, 100% of the 106 output operations are not properly escaped, meaning that any user-supplied data displayed on the frontend or backend could be vulnerable to cross-site scripting (XSS) attacks. The taint analysis also identified 3 flows with unsanitized paths, indicating potential for path traversal vulnerabilities, although these are not classified as critical or high severity in the provided data. The plugin's vulnerability history is empty, which could imply a history of good security practices or simply a lack of past discoveries. However, the identified code signals, particularly the unescaped output and use of `create_function`, present substantial risks that outweigh the absence of CVEs. A strong emphasis on output escaping and secure code practices is urgently needed.
Key Concerns
- Unescaped output across all operations
- Use of dangerous create_function
- Unsanitized paths in taint analysis
- No capability checks on entry points
- No nonce checks on entry points
PukiWiki for WordPress Security Vulnerabilities
PukiWiki for WordPress Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
PukiWiki for WordPress Attack Surface
WordPress Hooks 5
Maintenance & Trust
PukiWiki for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
PukiWiki for WordPress Alternatives
WP Multibyte Patch
wp-multibyte-patch
Multibyte functionality enhancement for the WordPress Japanese package.
Aurora Heatmap
aurora-heatmap
Beautiful like an aurora! A simple WordPress heatmap that can be completed with just a plugin.
Japanese font for WordPress(Previously: Japanese Font for TinyMCE)
japanese-font-for-tinymce
Add Japanese font to Gutenberg and TinyMCE Advanced plugin's font family selections.
Japanized for WooCommerce
woocommerce-for-japan
Essential Japanese localization toolkit for WooCommerce - adds address formats, payment methods, delivery scheduling, and legal compliance.
BuddyPress Docs
buddypress-docs
Adds collaborative Docs to BuddyPress.
PukiWiki for WordPress Developer Profile
3 plugins · 40 total installs
How We Detect PukiWiki for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pukiwiki-for-wordpress/pukiwiki.css/wp-content/plugins/pukiwiki-for-wordpress/admin.jsHTML / DOM Fingerprints
pukiwiki_content<div id="pukiwiki_content" class="pukiwiki_content">