Queerify Security & Risk Analysis

wordpress.org/plugins/queerify

Queerify your website by setting a fabulous loading screen that features a choosen flag from the LGBTIQ+ spectrum - representing your own gender ident …

0 active installs v1.0.7 PHP 5.6+ WP 4.9.8+ Updated May 19, 2020
lgbtloadingloading-screenqueer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Queerify Safe to Use in 2026?

Generally Safe

Score 85/100

Queerify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The queerify plugin version 1.0.7 demonstrates a generally positive security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, and all entry points, though none were identified, would be considered protected. The code signals further support this, with no dangerous functions, file operations, external HTTP requests, or critical taint flows detected. SQL queries are exclusively handled via prepared statements, which is a strong security practice.

However, there are areas for improvement. The output escaping rate of 27% is concerning, suggesting a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed. The lack of nonce checks on the identified capability checks is also a weakness, potentially leaving the plugin susceptible to cross-site request forgery (CSRF) attacks, especially if the capability checked grants access to sensitive operations. The complete absence of taint analysis flows is unusual and might indicate that the analysis tool was unable to trace any data flow, which could mask potential vulnerabilities.

The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the limited attack surface and the use of prepared statements, suggests that this version of the plugin has historically been secure. Nonetheless, the identified weaknesses in output escaping and the potential lack of robust CSRF protection warrant attention. While the plugin appears strong, the unaddressed output escaping issues represent a tangible risk.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks on capability checks
Vulnerabilities
None known

Queerify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Queerify Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
3 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

27% escaped11 total outputs
Attack Surface

Queerify Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_enqueue_scriptsclass-queerify.php:18
actionwp_enqueue_scriptsclass-queerify.php:20
actionadmin_initclass-queerify.php:22
actionadmin_menuclass-queerify.php:24
Maintenance & Trust

Queerify Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 19, 2020
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Queerify Developer Profile

Ivan Maljukanović

3 plugins · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Queerify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/queerify/resources/css/admin-style.css/wp-content/plugins/queerify/resources/js/admin-script.js/wp-content/plugins/queerify/resources/css/public-style-min.css/wp-content/plugins/queerify/resources/js/public-script-min.js/wp-content/plugins/queerify/resources/css/public-style.css/wp-content/plugins/queerify/resources/js/public-script.js
Script Paths
/wp-content/plugins/queerify/resources/js/admin-script.js/wp-content/plugins/queerify/resources/js/public-script-min.js/wp-content/plugins/queerify/resources/js/public-script.js
Version Parameters
queerify/resources/css/admin-style.css?ver=queerify/resources/js/admin-script.js?ver=queerify/resources/css/public-style-min.css?ver=queerify/resources/js/public-script-min.js?ver=queerify/resources/css/public-style.css?ver=queerify/resources/js/public-script.js?ver=

HTML / DOM Fingerprints

JS Globals
phpData
FAQ

Frequently Asked Questions about Queerify