
Scriptrr Google + Profile widget Security & Risk Analysis
wordpress.org/plugins/scriptrr-google-profileGoogle Plus Profile Widget allows users to add plugin on their blog or website to invite visitors to new Google + Profile.
Is Scriptrr Google + Profile widget Safe to Use in 2026?
Generally Safe
Score 85/100Scriptrr Google + Profile widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The scriptrr-google-profile plugin v0.7.1 exhibits a seemingly strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL injection vulnerabilities due to prepared statements, file operations, external HTTP requests, or cron events. Furthermore, the absence of known CVEs and a clean vulnerability history are positive indicators of the plugin's maintenance and security awareness. The plugin also boasts a very small attack surface with no identified entry points that are unprotected.
However, the analysis does reveal significant concerns, particularly regarding output escaping. With 10 total outputs and 0% properly escaped, there is a high likelihood of cross-site scripting (XSS) vulnerabilities. This lack of sanitization on output data could allow attackers to inject malicious scripts into the website, impacting users. Additionally, the complete absence of nonce and capability checks across all entry points, while the entry points are currently reported as zero, raises a red flag. If any new entry points are introduced or if the current count is an anomaly, these missing checks would create critical security gaps.
In conclusion, while the plugin benefits from a lack of known critical vulnerabilities and well-handled SQL queries, the pervasive issue with output escaping presents a substantial risk. The missing authorization checks, even with a small attack surface, also warrant attention. Developers should prioritize addressing the output escaping to mitigate XSS risks and ensure robust authorization mechanisms are in place for any future additions to the plugin's functionality.
Key Concerns
- 0% output escaping on 10 outputs
- 0 capability checks on entry points
- 0 nonce checks on entry points
Scriptrr Google + Profile widget Security Vulnerabilities
Scriptrr Google + Profile widget Release Timeline
Scriptrr Google + Profile widget Code Analysis
Output Escaping
Scriptrr Google + Profile widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Scriptrr Google + Profile widget Maintenance & Trust
Maintenance Signals
Community Trust
Scriptrr Google + Profile widget Alternatives
No alternatives data available yet.
Scriptrr Google + Profile widget Developer Profile
10 plugins · 1K total installs
How We Detect Scriptrr Google + Profile widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
scriptrr_google_plus_profile_widget-useridscriptrr_google_plus_profile_widget-widthscriptrr_google_plus_profile_widget-heightscriptrr_google_plus_profile_widget-hostscriptrr_google_plus_profile_widget-colorscriptrr_google_plus_profile_widget-links+1 more<iframe src="http://plus.scriptrr.com/scriptrr.php?id=