Renesse Aan Zee Security & Risk Analysis

wordpress.org/plugins/renesse-aan-zee

Renesse Aan Zee widget plugin.

0 active installs v1.1 PHP + WP 5.0+ Updated Feb 27, 2025
activiteitenevenementenrenesserenesseaanzeewidget
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Renesse Aan Zee Safe to Use in 2026?

Generally Safe

Score 92/100

Renesse Aan Zee has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'renesse-aan-zee' v1.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and properly escaping nearly all output. The absence of file operations and external HTTP requests also reduces potential attack vectors. However, the plugin presents significant concerns due to its unprotected REST API entry points. With two REST API routes identified and both lacking permission callbacks, these endpoints are directly accessible and could be exploited by unauthenticated users. The lack of any nonce or capability checks on these entry points further exacerbates this risk, creating a substantial attack surface that is unprotected. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator. However, this clean history, coupled with the identified security weaknesses, might suggest a lack of targeted security testing or a limited attack surface that hasn't been thoroughly probed. Overall, while the plugin adheres to some security best practices, the unprotected REST API routes are a critical vulnerability that significantly elevates its risk profile.

Key Concerns

  • REST API routes without permission callbacks
  • Entry points without authentication checks
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Renesse Aan Zee Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Renesse Aan Zee Release Timeline

v1.1Current
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Renesse Aan Zee Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped33 total outputs
Attack Surface
2 unprotected

Renesse Aan Zee Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

GET/wp-json/renesse/v1/check-data-timestampfunctions/check-data-timestamp.php:6
POST/wp-json/renesse/v1/save-datafunctions/save-data-api.php:6
WordPress Hooks 6
actionrest_api_initfunctions/check-data-timestamp.php:5
actionrest_api_initfunctions/save-data-api.php:5
actionwp_footerfunctions/widget-controller.php:507
actionwp_enqueue_scriptsrenesse-aan-zee.php:33
actionadmin_menurenesse-aan-zee.php:42
actionadmin_initrenesse-aan-zee.php:48
Maintenance & Trust

Renesse Aan Zee Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 27, 2025
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Renesse Aan Zee Developer Profile

Kevin Landsbergen

2 plugins · 3K total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Renesse Aan Zee

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/renesse-aan-zee/update-api.js
Script Paths
/wp-content/plugins/renesse-aan-zee/update-api.js

HTML / DOM Fingerprints

CSS Classes
renesse-yellowrenesse-greenrenesse-bluewidget-rightwidget-leftrenesse-widget-containercarousel-itemcard+3 more
Data Attributes
renesse_widget_plugin_position
JS Globals
renesse_widget_eventsrenesse_widget_activitiesrenesse_widget_plugin_position
Shortcode Output
<div id="renesse-widget-container"></div>
FAQ

Frequently Asked Questions about Renesse Aan Zee