
Scholar Publications Fetcher Security & Risk Analysis
wordpress.org/plugins/scholar-publications-fetcherFetch, cache, customize, and display Google Scholar profiles and publications with an easy WordPress admin settings panel.
Is Scholar Publications Fetcher Safe to Use in 2026?
Generally Safe
Score 100/100Scholar Publications Fetcher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scholar-publications-fetcher" v2.2.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, 100% usage of prepared statements for SQL queries, and proper output escaping are all excellent indicators of secure coding practices. Furthermore, the plugin has no recorded vulnerabilities or CVEs, suggesting a history of well-maintained and secure development.
While the static analysis does not reveal any immediate critical flaws like unsanitized taint flows or raw SQL queries, there are areas for potential concern. The lack of nonce checks on its single shortcode entry point, along with a complete absence of capability checks, presents a potential avenue for unauthorized actions if the shortcode's functionality is sensitive. Additionally, the presence of external HTTP requests, though not inherently problematic, always warrants careful scrutiny for potential vulnerabilities related to the external services it interacts with.
Overall, the plugin appears to be developed with security in mind, particularly in its data handling. However, the missing client-side and server-side authorization checks on the shortcode are a notable weakness that could be exploited. The lack of vulnerability history is a positive sign, but it does not completely absolve the plugin from potential future undiscovered issues, especially considering the identified lack of authorization controls.
Key Concerns
- Missing nonce checks on shortcode
- Missing capability checks on entry points
Scholar Publications Fetcher Security Vulnerabilities
Scholar Publications Fetcher Release Timeline
Scholar Publications Fetcher Code Analysis
SQL Query Safety
Output Escaping
Scholar Publications Fetcher Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Scholar Publications Fetcher Maintenance & Trust
Maintenance Signals
Community Trust
Scholar Publications Fetcher Alternatives
Researcher Profiles for ORCID
researcher-profiles-for-orcid
Fetch, cache and display researcher profiles from the ORCID Public API via shortcodes. No live API calls on page load.
Zotpress
zotpress
Zotpress displays your Zotero citations on WordPress.
Academic Publications Showcase
academic-publications-showcase
Display publications from Zenodo communities or ORCID author profiles with modern card layouts and customizable designs.
Citrus
citrus
Display research publications from Pure API or manually provided BibTeX data beautifully.
Publiton – Auto Publication Updater
publiton-auto-publication-updater
Auto-updating academic publication lists. Enter your ORCID iD once — your list keeps itself current, powered by OpenAlex.
Scholar Publications Fetcher Developer Profile
1 plugin · 200 total installs
How We Detect Scholar Publications Fetcher
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scholar-publications-fetcher/css/gs-styles.cssscholar-publications-fetcher/css/gs-styles.css?ver=HTML / DOM Fingerprints
gsc_a_trgsc_a_atgs_graygsc_a_hcgsc_oci_descrgsc_a_atgsc_a_hcgsc_oci_descr[schopufe_publicationsuser_idcountshow_abstract