
Scriblio Security & Risk Analysis
wordpress.org/plugins/scriblioScriblio enables faceted searching and browsing of WordPress posts, pages, and custom post types.
Is Scriblio Safe to Use in 2026?
Generally Safe
Score 85/100Scriblio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scriblio" plugin v3.3 presents a mixed security posture. While it has no recorded vulnerability history (CVEs), the static analysis reveals significant concerns. The plugin exposes an unprotected AJAX handler, which is a critical entry point for potential attacks. The taint analysis indicates multiple flows with unsanitized paths, with three flagged as high severity, suggesting potential for injecting malicious data or commands. Additionally, the plugin utilizes dangerous functions like `unserialize` and `set_time_limit`, and a concerning 57% of its output is not properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities. The absence of nonce checks on the exposed AJAX handler is a major oversight. The limited capability checks also contribute to a weaker security posture. Despite the lack of historical CVEs, the identified code-level weaknesses, particularly the unprotected AJAX endpoint and high-severity taint flows, warrant careful consideration and mitigation.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized taint flows (3)
- Use of dangerous functions (unserialize)
- Low output escaping percentage (43%)
- Missing nonce checks
- Limited capability checks (2)
Scriblio Security Vulnerabilities
Scriblio Release Timeline
Scriblio Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Scriblio Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 23
Maintenance & Trust
Scriblio Maintenance & Trust
Maintenance Signals
Community Trust
Scriblio Alternatives
WP Books Gallery – Build Stunning Book Showcases & Libraries in Minutes
wp-books-gallery
WordPress Book Gallery will build a mobile-friendly book gallery, book showcase, or book library in a few minutes.
RS WP Book Showcase – A Complete Book Catalogue & Library System
rs-wp-books-showcase
Premier WordPress book gallery plugin, offering advanced search options and multiple layouts for effortless book showcasing.
Library Bookshelves
library-bookshelves
Create bookshelves that link to your library catalog. Use shortcodes to display book covers in carousels.
BNC BiblioShare
bnc-biblioshare
Displays a book's cover image, title, author, and other book data from BiblioShare
Bestseller Lists from the New York Times
bestseller-lists-from-new-york-times
Integrate bestseller lists from the New York Times into your own site with a user-friendly interface.
Scriblio Developer Profile
8 plugins · 290 total installs
How We Detect Scriblio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scriblio/css/editor.css/wp-content/plugins/scriblio/js/editor.js/wp-content/plugins/scriblio/js/jquery.keyboard-a11y.js/wp-content/plugins/scriblio/js/editor.js/wp-content/plugins/scriblio/js/jquery.keyboard-a11y.jsHTML / DOM Fingerprints
scrib_meditor_endfieldset_titleid="scrib_meditor"id="scrib_meditor-search-search"scriblio[scrib_availability]