RankRiskIndex Security & Risk Analysis

wordpress.org/plugins/rankriskindex

This plugin shows the daily updated Rank Risk Index by Rank Ranger

10 active installs v1.3 PHP + WP 3.0+ Updated Dec 12, 2016
dashboard-widgetgooglerankingsrankrangerseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RankRiskIndex Safe to Use in 2026?

Generally Safe

Score 85/100

RankRiskIndex has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin "rankriskindex" v1.3 exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the plugin's clean vulnerability history suggest a commitment to security or a lack of discovered vulnerabilities. The code analysis reveals no dangerous functions, no direct SQL queries (all are prepared), no file operations, and no external HTTP requests, which are all strong security indicators. Furthermore, the limited attack surface, consisting of a single shortcode with no apparent immediate unprotected entry points, is a positive sign. However, a significant concern arises from the output escaping. With 22% of outputs properly escaped, a substantial portion (78%) may be vulnerable to cross-site scripting (XSS) attacks. The lack of nonce and capability checks is also a notable weakness, especially if the shortcode handler performs sensitive operations or interacts with user data.

Key Concerns

  • Low percentage of properly escaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

RankRiskIndex Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

RankRiskIndex Release Timeline

v1.3Current
v1.2
v1.01
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

RankRiskIndex Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped9 total outputs
Attack Surface

RankRiskIndex Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[rankrisk] rankriskindex.php:103
WordPress Hooks 2
actionwp_dashboard_setuprankriskindex.php:25
actionwidgets_initrankriskindex.php:94
Maintenance & Trust

RankRiskIndex Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedDec 12, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

RankRiskIndex Developer Profile

Jonathan Griffin

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RankRiskIndex

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<iframe src="https://www.rankranger.com/serp-fluctuations" frameborder="0" width="450" height="200" style="border: solid 1px #D7D7D7;"></iframe>
FAQ

Frequently Asked Questions about RankRiskIndex