๐Ÿ“ท Simple QR Code Generator Widget Security & Risk Analysis

wordpress.org/plugins/qr-code-generator-widget

Simple QR Code Generator

400 active installs v1.10 PHP + WP 2.0.2+ Updated Jul 4, 2024
bar-code-generatorcodeqrsimple-bar-code-generatorsimple-qr-code
92
A ยท Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ๐Ÿ“ท Simple QR Code Generator Widget Safe to Use in 2026?

Generally Safe

Score 92/100

๐Ÿ“ท Simple QR Code Generator Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "qr-code-generator-widget" plugin version 1.10 exhibits a mixed security posture. On the positive side, the static analysis shows no reported vulnerabilities in its history, no dangerous functions, and all SQL queries utilize prepared statements. Furthermore, there are no observed file operations or external HTTP requests, which generally limits potential attack vectors.

However, a significant concern arises from the output escaping. With 12 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the plugin that originates from user input or external sources is likely to be rendered directly in the browser without sanitization, making it susceptible to injection attacks. The absence of nonce checks and capability checks also means that if any entry points were to be discovered or introduced in future versions, they might not be adequately protected against unauthorized actions.

Overall, while the plugin appears to have avoided historical vulnerabilities and maintains good practices in areas like SQL and avoiding dangerous functions, the lack of output escaping is a critical flaw that significantly elevates the risk. This weakness overshadows the strengths and requires immediate attention to prevent potential XSS attacks.

Key Concerns

  • Output escaping not properly handled
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

๐Ÿ“ท Simple QR Code Generator Widget Security Vulnerabilities

No known vulnerabilities โ€” this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

๐Ÿ“ท Simple QR Code Generator Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped12 total outputs
Attack Surface

๐Ÿ“ท Simple QR Code Generator Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionplugins_loadedqrCode.php:155
Maintenance & Trust

๐Ÿ“ท Simple QR Code Generator Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedJul 4, 2024
PHP min version
Downloads17K

Community Trust

Rating100/100
Number of ratings1
Active installs400
Developer Profile

๐Ÿ“ท Simple QR Code Generator Widget Developer Profile

nemezis

1 plugin ยท 400 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ๐Ÿ“ท Simple QR Code Generator Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
widget-content
Data Attributes
onchange="widgetHeightInfo.value=value"onchange="widgetWidthInfo.value=value"
FAQ

Frequently Asked Questions about ๐Ÿ“ท Simple QR Code Generator Widget