
References Security & Risk Analysis
wordpress.org/plugins/referencesEnables post references (for any type of publications) to connect articles to each other.
Is References Safe to Use in 2026?
Generally Safe
Score 92/100References has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "references" plugin version 1.202 exhibits a mixed security posture. While it shows strengths in its limited attack surface, absence of external requests, and basic nonce check, significant concerns arise from its code analysis. The presence of the `unserialize()` function is a major red flag, as it can lead to remote code execution vulnerabilities if used with untrusted input. Furthermore, the low percentage of properly escaped outputs (16%) indicates a high risk of cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a positive sign, suggesting that the developers may have a good track record or that the plugin hasn't been extensively targeted. However, this absence of history should not overshadow the inherent risks identified in the static analysis. The lack of capability checks is also a concern, as it implies that actions performed by the plugin might not be properly restricted to authorized users.
In conclusion, while the "references" plugin has a small attack surface and a clean vulnerability history, the identified code weaknesses, particularly `unserialize()` and poor output escaping, present substantial security risks. These issues require immediate attention to mitigate potential exploits and ensure the plugin's secure operation. The absence of capability checks further weakens its security posture.
Key Concerns
- Dangerous function unserialize found
- Low percentage of output escaping
- SQL queries not always prepared
- No capability checks on entry points
References Security Vulnerabilities
References Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
References Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
References Maintenance & Trust
Maintenance Signals
Community Trust
References Alternatives
Footnotes Made Easy
footnotes-made-easy
Allows post authors to easily add and manage footnotes in posts.
Resizable Sidebar for the Gutenberg Block Editor
resizable-editor-sidebar
An intuitive solution to make the default WordPress Gutenberg sidebar resizable.
Simple Footnotes
simple-footnotes
Create simple, elegant footnotes on your site. Use the [ref] shortcode and the plugin takes care of the rest.
BibleLink Multilingual
bible-link-multilingual
This lightweight plugin makes Bible references on your website interactive and supports multiple languages.
Blank Footnotes
blank-footnotes
Simple plugin to show footnotes using markdown notation.
References Developer Profile
43 plugins · 19K total installs
How We Detect References
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/references/js/admin.js/wp-content/plugins/references/css/admin.css/wp-content/plugins/references/js/admin.jsver=1.202HTML / DOM Fingerprints
<!-- REFShraAPI --><!-- References PLugin Class -->data-post_iddata-ref_keyREFShraAPI<div class="ref-block">