Scriptrr Google + Profile widget Security & Risk Analysis

wordpress.org/plugins/scriptrr-google-profile

Google Plus Profile Widget allows users to add plugin on their blog or website to invite visitors to new Google + Profile.

10 active installs v0.7.1 PHP + WP 2.0.2+ Updated Aug 12, 2011
scriptrr-google-plus-profile-widget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Scriptrr Google + Profile widget Safe to Use in 2026?

Generally Safe

Score 85/100

Scriptrr Google + Profile widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The scriptrr-google-profile plugin v0.7.1 exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL injection vulnerabilities due to prepared statements, file operations, external HTTP requests, or cron events. Furthermore, the absence of known CVEs and a clean vulnerability history are positive indicators of the plugin's maintenance and security awareness. The plugin also boasts a very small attack surface with no identified entry points that are unprotected.

However, the analysis does reveal significant concerns, particularly regarding output escaping. With 10 total outputs and 0% properly escaped, there is a high likelihood of cross-site scripting (XSS) vulnerabilities. This lack of sanitization on output data could allow attackers to inject malicious scripts into the website, impacting users. Additionally, the complete absence of nonce and capability checks across all entry points, while the entry points are currently reported as zero, raises a red flag. If any new entry points are introduced or if the current count is an anomaly, these missing checks would create critical security gaps.

In conclusion, while the plugin benefits from a lack of known critical vulnerabilities and well-handled SQL queries, the pervasive issue with output escaping presents a substantial risk. The missing authorization checks, even with a small attack surface, also warrant attention. Developers should prioritize addressing the output escaping to mitigate XSS risks and ensure robust authorization mechanisms are in place for any future additions to the plugin's functionality.

Key Concerns

  • 0% output escaping on 10 outputs
  • 0 capability checks on entry points
  • 0 nonce checks on entry points
Vulnerabilities
None known

Scriptrr Google + Profile widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Scriptrr Google + Profile widget Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Scriptrr Google + Profile widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped10 total outputs
Attack Surface

Scriptrr Google + Profile widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initscriptrr_google_plus_profile_widget.php:141
Maintenance & Trust

Scriptrr Google + Profile widget Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedAug 12, 2011
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Scriptrr Google + Profile widget Alternatives

No alternatives data available yet.

Developer Profile

Scriptrr Google + Profile widget Developer Profile

Sandeep Verma

10 plugins · 1K total installs

65
trust score
Avg Security Score
80/100
Avg Patch Time
392 days
View full developer profile
Detection Fingerprints

How We Detect Scriptrr Google + Profile widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
scriptrr_google_plus_profile_widget-useridscriptrr_google_plus_profile_widget-widthscriptrr_google_plus_profile_widget-heightscriptrr_google_plus_profile_widget-hostscriptrr_google_plus_profile_widget-colorscriptrr_google_plus_profile_widget-links+1 more
Shortcode Output
<iframe src="http://plus.scriptrr.com/scriptrr.php?id=
FAQ

Frequently Asked Questions about Scriptrr Google + Profile widget