
Checklist Opquast Qualité Web Security & Risk Analysis
wordpress.org/plugins/quality-checklist-opquastQualité Web : les bonnes pratiques web dans une checklist de 226 critères de référence
Is Checklist Opquast Qualité Web Safe to Use in 2026?
Generally Safe
Score 100/100Checklist Opquast Qualité Web has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the quality-checklist-opquast plugin v0.2 appears to be generally positive based on the static analysis. The plugin boasts a small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential entry points for attackers. Furthermore, the code shows good practices in its handling of SQL queries, with 100% of them utilizing prepared statements, and a basic nonce check is present. There are no identified critical or high-severity taint flows, and the vulnerability history is clean, with no recorded CVEs.
However, there are notable areas of concern. The most significant is the extremely low rate of proper output escaping, with only 14% of 36 total outputs being correctly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, while a nonce check exists, there are no capability checks implemented on any entry points, leaving them potentially open to unauthorized access if any were to be discovered. The presence of file operations without further context also warrants caution, as these could be potential vectors for abuse if not handled with extreme care.
In conclusion, the plugin has strengths in its limited attack surface and secure SQL handling. However, the widespread lack of output escaping is a critical weakness that significantly increases the risk of XSS attacks. The absence of capability checks on entry points is another concern. Until the output escaping issues are addressed, the plugin should be considered to have a moderate to high security risk.
Key Concerns
- Low output escaping rate
- No capability checks on entry points
Checklist Opquast Qualité Web Security Vulnerabilities
Checklist Opquast Qualité Web Code Analysis
Output Escaping
Checklist Opquast Qualité Web Attack Surface
WordPress Hooks 3
Maintenance & Trust
Checklist Opquast Qualité Web Maintenance & Trust
Maintenance Signals
Community Trust
Checklist Opquast Qualité Web Alternatives
PublishPress Checklists: Pre-Publishing Approval Checklist – Validate Post Requirements
publishpress-checklists
Define checklist tasks to complete before publishing posts. Make sure your content meets your requirements.
Pre-Publish Checklist
pre-publish-checklist
Easiest way to make sure your page or post is ready to go live
Checklist
checklist
Turn any list in your blog to a beautiful interactive checklist. Print, Use, Share, Download to Mobile and more. 100% Free.
Checklist in Post
checklist-in-post
Allow creating checklists in posts based on bulleted list.
Publishing Checklist
publishing-checklist
Pre-flight your posts.
Checklist Opquast Qualité Web Developer Profile
24 plugins · 64K total installs
How We Detect Checklist Opquast Qualité Web
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/quality-checklist-opquast/css/opquast-styles.css/wp-content/plugins/quality-checklist-opquast/js/opquast-scripts.js/wp-content/plugins/quality-checklist-opquast/js/opquast-scripts.jsquality-checklist-opquast/css/opquast-styles.css?ver=quality-checklist-opquast/js/opquast-scripts.js?ver=HTML / DOM Fingerprints
opquast-buttonsite-healthopquast-statsopquast-stat-greenopquast-stat-redopquast-stat-blueopquast-stat-greyopquast-licence+1 moredata-opquastopquast_var_langopquast_var_ajaxurlopquast_var_ajaxnonceopquast_var_data_fropquast_var_data_fr_contentopquast_var_data_fr_thematiques