Risk List Security & Risk Analysis

wordpress.org/plugins/risk-list

Risk List brings Risk Management into your WordPress Dashboard. Manage your risks. Track your Metrics. Grow big.

10 active installs v1.0 PHP + WP 4.6+ Updated Jan 9, 2017
risk-managementrisks
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Risk List Safe to Use in 2026?

Generally Safe

Score 85/100

Risk List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "risk-list" v1.0 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The complete absence of any known CVEs, coupled with zero critical or high severity vulnerabilities in its history, suggests a development team that is either highly diligent or has not yet attracted significant security scrutiny. The static analysis reveals a very small attack surface with no identified unprotected entry points, which is a strong indicator of secure coding practices in this regard. Furthermore, the presence of nonce checks is encouraging.

However, significant concerns arise from the output escaping and SQL query practices. With 100% of outputs not properly escaped, there is a very high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin is susceptible to malicious injection. While 50% of SQL queries utilize prepared statements, the remaining half are potentially vulnerable to SQL injection, especially if they handle user-supplied input without proper sanitization, though the taint analysis didn't find any such flows.

The plugin's lack of capability checks is also a notable weakness, as it implies that access to certain functionalities might not be properly restricted to authorized users. This, combined with the unescaped output, creates a concerning environment for potential privilege escalation or data manipulation if certain functionalities are accessible to lower-privileged users. Despite the clean vulnerability history, the identified coding issues in output escaping and capability checks necessitate immediate attention to mitigate these risks.

Key Concerns

  • 0% properly escaped output
  • 50% SQL queries not prepared
  • 0 capability checks
Vulnerabilities
None known

Risk List Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Risk List Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
6 prepared
Unescaped Output
126
0 escaped
Nonce Checks
10
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared12 total queries

Output Escaping

0% escaped126 total outputs
Attack Surface

Risk List Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 32
actionwp_dashboard_setupincludes\risk-list-dashboard.php:38
actionadd_meta_boxesincludes\risk-list-risk-meta.php:28
filtersave_postincludes\risk-list-risk-meta.php:29
actionadd_meta_boxesincludes\risk-list-risk-meta.php:122
filtersave_postincludes\risk-list-risk-meta.php:123
actionadd_meta_boxesincludes\risk-list-risk-meta.php:220
filtersave_postincludes\risk-list-risk-meta.php:221
actionadd_meta_boxesincludes\risk-list-risk-meta.php:315
filtersave_postincludes\risk-list-risk-meta.php:316
actionadd_meta_boxesincludes\risk-list-risk-meta.php:409
filtersave_postincludes\risk-list-risk-meta.php:410
actionadd_meta_boxesincludes\risk-list-risk-meta.php:695
filtersave_postincludes\risk-list-risk-meta.php:696
actionadd_meta_boxesincludes\risk-list-risk-meta.php:842
filtersave_postincludes\risk-list-risk-meta.php:843
actionadd_meta_boxesincludes\risk-list-risk-meta.php:960
filtersave_postincludes\risk-list-risk-meta.php:961
actionadd_meta_boxesincludes\risk-list-risk-meta.php:1054
filtersave_postincludes\risk-list-risk-meta.php:1055
actionadd_meta_boxesincludes\risk-list-risk-meta.php:1132
filtersave_postincludes\risk-list-risk-meta.php:1133
actioninitrisk-list.php:30
actionadmin_initrisk-list.php:31
actionadmin_menurisk-list.php:188
actionrestrict_manage_postsrisk-list.php:869
actionadmin_enqueue_scriptsrisk-list.php:910
filtermanage_risklist_risk_posts_columnsrisk-list.php:949
actionmanage_risklist_risk_posts_custom_columnrisk-list.php:950
actionadmin_footerrisk-list.php:1103
filtermanage_risklist_risk_columnsrisk-list.php:1119
filteradmin_footer_textrisk-list.php:1134
filterupdate_footerrisk-list.php:1140
Maintenance & Trust

Risk List Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedJan 9, 2017
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Risk List Developer Profile

Mike Stott

3 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Risk List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/risk-list/css/risk-list.css/wp-content/plugins/risk-list/js/risk-list.js
Script Paths
/wp-content/plugins/risk-list/js/risk-list.js
Version Parameters
risk-list/css/risk-list.css?ver=risk-list/js/risk-list.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!--COMMENT} Define Paths<!--COMMENT} Risk Manager#COMMENT} For all zerobs users :)<!-- COMMENT} Translations+1 more
FAQ

Frequently Asked Questions about Risk List