Scriptrr Google + Activity Feed widget Security & Risk Analysis

wordpress.org/plugins/scriptrr-google-activity-feed-widget

Google Plus Activity Feed Widget allows users to add plugin on their blog or website to explore latest posts / feeds on Google + Profile.

10 active installs v0.7.1 PHP + WP 2.0.2+ Updated Aug 14, 2011
scriptrr-google-plus-activity-feed-live-stream-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scriptrr Google + Activity Feed widget Safe to Use in 2026?

Generally Safe

Score 85/100

Scriptrr Google + Activity Feed widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The security posture of the scriptrr-google-activity-feed-widget plugin version 0.7.1 appears to be strong based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the analysis indicates no dangerous functions, no file operations, and no external HTTP requests, all of which are positive indicators. The fact that all SQL queries use prepared statements and there are no recorded CVEs or vulnerability history suggests a well-maintained and secure codebase.

However, a notable concern arises from the output escaping analysis. With 10 total outputs and 0% properly escaped, this presents a significant risk. Any user-supplied data that is not properly escaped before being displayed to the user could lead to cross-site scripting (XSS) vulnerabilities. While the taint analysis shows no unsanitized paths, this could be due to the limited attack surface or that the taint analysis itself was not comprehensive enough to identify these flows. The lack of nonce checks and capability checks, while not directly leading to issues in this version due to the limited attack surface, represents a weakness that could be exploited if new entry points were introduced in future updates.

In conclusion, the plugin exhibits good practices by minimizing its attack surface and employing prepared statements for SQL. The absence of known vulnerabilities is also a strong positive. The primary and most immediate risk stems from the complete lack of output escaping, which warrants immediate attention. While the current lack of exploits might be circumstantial, the underlying insecurity in output handling needs to be addressed to prevent potential XSS attacks.

Key Concerns

  • All outputs unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Scriptrr Google + Activity Feed widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Scriptrr Google + Activity Feed widget Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Scriptrr Google + Activity Feed widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped10 total outputs
Attack Surface

Scriptrr Google + Activity Feed widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initscriptrr_google_plus_activity_feed_widget.php:146
Maintenance & Trust

Scriptrr Google + Activity Feed widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedAug 14, 2011
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Scriptrr Google + Activity Feed widget Alternatives

No alternatives data available yet.

Developer Profile

Scriptrr Google + Activity Feed widget Developer Profile

Sandeep Verma

10 plugins · 1K total installs

65
trust score
Avg Security Score
80/100
Avg Patch Time
392 days
View full developer profile
Detection Fingerprints

How We Detect Scriptrr Google + Activity Feed widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
scriptrr_google_plus_activity_feed_widget-titlescriptrr_google_plus_activity_feed_widget-useridscriptrr_google_plus_activity_feed_widget-widthscriptrr_google_plus_activity_feed_widget-heightscriptrr_google_plus_activity_feed_widget-hostscriptrr_google_plus_activity_feed_widget-color+1 more
Shortcode Output
<iframe src="http://plus.scriptrr.com/feeds/feeds.php?plusid=&host=&height=&width=
FAQ

Frequently Asked Questions about Scriptrr Google + Activity Feed widget