RAWR for WordPress Security & Risk Analysis

wordpress.org/plugins/rawr

You got information - we got conversation! Rawr widgets sit right within the story and help your users to express and share their opinion with others.

10 active installs v0.1.0 PHP + WP 3.3.0+ Updated Jun 2, 2017
analyticsmarketingopinionpollsurvey
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RAWR for WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

RAWR for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'rawr' plugin v0.1.0 exhibits a generally good security posture, with no known vulnerabilities or critical code issues detected. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong positive. The presence of nonce and capability checks on all identified entry points (AJAX handlers and shortcodes) indicates a conscious effort to implement basic security measures. However, a significant concern arises from the output escaping, where only 38% of outputs are properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if the unescaped outputs handle user-supplied data or dynamic content. While the current version shows no historical vulnerabilities, the low version number (0.1.0) suggests it's still in early development, and the limited static analysis scope (0 taint flows) may not have revealed deeper issues. The plugin's small attack surface is a mitigating factor, but the output escaping deficiency warrants attention.

Key Concerns

  • Low output escaping percentage
Vulnerabilities
None known

RAWR for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

RAWR for WordPress Release Timeline

v0.0.7
v0.0.6
v0.0.5
v0.0.4.1
Code Analysis
Analyzed Apr 16, 2026

RAWR for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
5 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

38% escaped13 total outputs
Attack Surface

RAWR for WordPress Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_rawr_handleradmin/ajax-actions.php:15

Shortcodes 1

[rawr] public/class-rawr-public.php:115
WordPress Hooks 15
actionplugins_loadedincludes/class-rawr.php:143
actionadmin_initincludes/class-rawr.php:155
actionadmin_enqueue_scriptsincludes/class-rawr.php:156
actionadmin_enqueue_scriptsincludes/class-rawr.php:157
actionadd_meta_boxesincludes/class-rawr.php:158
actionsave_postincludes/class-rawr.php:159
actionadmin_bar_menuincludes/class-rawr.php:160
actionadmin_noticesincludes/class-rawr.php:161
actionadmin_menuincludes/class-rawr.php:162
actionadmin_footer_textincludes/class-rawr.php:163
actionwp_enqueue_scriptsincludes/class-rawr.php:176
actionwp_enqueue_scriptsincludes/class-rawr.php:177
actioninitincludes/class-rawr.php:178
filterthe_contentincludes/class-rawr.php:179
actionadmin_initrawr.php:32
Maintenance & Trust

RAWR for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedJun 2, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

RAWR for WordPress Developer Profile

natterstefan

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RAWR for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rawr/common/vendor/tether-shepherd/shepherd-theme-arrows.css/wp-content/plugins/rawr/common/css/bootstrap-wp.min.css/wp-content/plugins/rawr/common/vendor/flat-social-icons/flat-icons.css/wp-content/plugins/rawr/admin/css/rawr-admin.min.css
Script Paths
/wp-content/plugins/rawr/admin/js/rawr-admin-edit.min.js/wp-content/plugins/rawr/common/vendor/tether-shepherd/tether.js/wp-content/plugins/rawr/common/vendor/tether-shepherd/shepherd.min.js/wp-content/plugins/rawr/admin/js/rawr-admin.min.js
Version Parameters
rawr-admin-edit.min.css?ver=shepherd-theme-arrows.css?ver=bootstrap-wp.min.css?ver=flat-icons.css?ver=rawr-admin.min.css?ver=rawr-admin-edit.min.js?ver=tether.js?ver=shepherd.min.js?ver=rawr-admin.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
rawr-dashboard-widgetsrawr-admin-edit-wraprawr-headline-wraprawr-custom-text-wraprawr-social-share-buttonsrawr-content-wrap
HTML Comments
<!-- RAWR_ADMIN_AJAX --><!-- RAWR_ADMIN_OPTIONS --><!-- RAWR_ADMIN_POST_OPTIONS --><!-- RAWR_ADMIN_WIDGETS -->+3 more
Data Attributes
data-rawr-widgetdata-rawr-post-iddata-rawr-user-iddata-rawr-widget-iddata-rawr-widget-settingsdata-rawr-options+7 more
JS Globals
rawrAdminrawrAdminPostOptions
REST Endpoints
/wp-json/rawr/v1/widgets/wp-json/rawr/v1/options
Shortcode Output
[rawr_widget][rawr_social_share][rawr_headline][rawr_custom_text]
FAQ

Frequently Asked Questions about RAWR for WordPress