Showcase It – Display Projects, Products, or Media in Grid or Slider Security & Risk Analysis

wordpress.org/plugins/showcase-it

A lite Weight Plugin that helps you, Easily showcase your Books and other items in your WordPress Website in Post, Page, Widget Area using shortCode.

0 active installs v1.0.4 PHP 7.1+ WP 5.1+ Updated Feb 26, 2026
360-degree3dbook-showcasemovieshowcase
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Showcase It – Display Projects, Products, or Media in Grid or Slider Safe to Use in 2026?

Generally Safe

Score 100/100

Showcase It – Display Projects, Products, or Media in Grid or Slider has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "showcase-it" v1.0.4 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history is a significant positive indicator. The code demonstrates good practices by using prepared statements for all SQL queries and implementing a substantial number of nonce and capability checks, suggesting an effort to protect against common WordPress exploits.

However, a notable area for improvement lies in output escaping. With 74% of outputs properly escaped, there's a remaining 26% that could potentially expose the plugin to Cross-Site Scripting (XSS) vulnerabilities. While no critical or high severity taint flows were identified, the unescaped outputs represent a tangible risk that should be addressed. The plugin's attack surface, though entirely protected by authentication checks according to the analysis, is comprised of several entry points, making rigorous output sanitization crucial to prevent potential exploits from unexpected vectors.

Overall, "showcase-it" v1.0.4 benefits from a lack of known vulnerabilities and good database query security. The primary concern is the unescaped output, which, while not currently associated with a critical flaw, represents a weakness that could be exploited. Addressing this would further solidify the plugin's security, making it a more robust and reliable choice.

Key Concerns

  • Unescaped output detected (26%)
Vulnerabilities
None known

Showcase It – Display Projects, Products, or Media in Grid or Slider Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Showcase It – Display Projects, Products, or Media in Grid or Slider Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
224
622 escaped
Nonce Checks
12
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

74% escaped846 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
csf_export (inc\csf\functions\actions.php:62)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Showcase It – Display Projects, Products, or Media in Grid or Slider Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 5

authwp_ajax_csf-get-iconsinc\csf\functions\actions.php:50
authwp_ajax_csf-exportinc\csf\functions\actions.php:87
authwp_ajax_csf-importinc\csf\functions\actions.php:123
authwp_ajax_csf-resetinc\csf\functions\actions.php:150
authwp_ajax_csf-choseninc\csf\functions\actions.php:189

Shortcodes 1

[showcase] showcase.php:361
WordPress Hooks 63
actionadmin_enqueue_scriptsadmin\ads\submenu.php:10
actionadmin_menuadmin\ads\submenu.php:20
actionadmin_menuadmin\ads\submenu.php:105
actioninitadmin\ads\submenu.php:129
actionadmin_menuadmin\ads\submenu.php:137
actionwp_enqueue_scriptsinc\csf\classes\abstract.class.php:20
actionadmin_menuinc\csf\classes\admin-options.class.php:106
actionadmin_bar_menuinc\csf\classes\admin-options.class.php:107
actionnetwork_admin_menuinc\csf\classes\admin-options.class.php:111
filteradmin_footer_textinc\csf\classes\admin-options.class.php:487
actionadd_meta_boxes_commentinc\csf\classes\comment-options.class.php:38
actionedit_commentinc\csf\classes\comment-options.class.php:39
actioncustomize_registerinc\csf\classes\customize-options.class.php:43
actioncustomize_save_afterinc\csf\classes\customize-options.class.php:44
actionwp_enqueue_scriptsinc\csf\classes\customize-options.class.php:48
actionadd_meta_boxesinc\csf\classes\metabox-options.class.php:50
actionsave_postinc\csf\classes\metabox-options.class.php:51
actionedit_attachmentinc\csf\classes\metabox-options.class.php:52
actionwp_nav_menu_item_custom_fieldsinc\csf\classes\nav-menu-options.class.php:30
actionwp_update_nav_menu_iteminc\csf\classes\nav-menu-options.class.php:31
filterwp_edit_nav_menu_walkerinc\csf\classes\nav-menu-options.class.php:33
actionadmin_initinc\csf\classes\profile-options.class.php:30
actionshow_user_profileinc\csf\classes\profile-options.class.php:42
actionedit_user_profileinc\csf\classes\profile-options.class.php:43
actionpersonal_options_updateinc\csf\classes\profile-options.class.php:45
actionedit_user_profile_updateinc\csf\classes\profile-options.class.php:46
actionafter_setup_themeinc\csf\classes\setup.class.php:53
actioninitinc\csf\classes\setup.class.php:54
actionswitch_themeinc\csf\classes\setup.class.php:55
actionadmin_enqueue_scriptsinc\csf\classes\setup.class.php:56
actionwp_enqueue_scriptsinc\csf\classes\setup.class.php:57
actionwp_headinc\csf\classes\setup.class.php:58
filteradmin_body_classinc\csf\classes\setup.class.php:59
actionadmin_footerinc\csf\classes\shortcode-options.class.php:47
actioncustomize_controls_print_footer_scriptsinc\csf\classes\shortcode-options.class.php:48
actionelementor/editor/before_enqueue_scriptsinc\csf\classes\shortcode-options.class.php:57
actionelementor/editor/footerinc\csf\classes\shortcode-options.class.php:58
actionelementor/editor/footerinc\csf\classes\shortcode-options.class.php:59
actionenqueue_block_editor_assetsinc\csf\classes\shortcode-options.class.php:299
actionmedia_buttonsinc\csf\classes\shortcode-options.class.php:303
actionadmin_initinc\csf\classes\taxonomy-options.class.php:41
actionadmin_footerinc\csf\fields\icon\icon.php:41
actioncustomize_controls_print_footer_scriptsinc\csf\fields\icon\icon.php:42
actionadmin_print_footer_scriptsinc\csf\fields\link\link.php:65
actionprint_default_editor_scriptsinc\csf\fields\wp_editor\wp_editor.php:62
actionadmin_menuinc\csf\views\welcome.php:19
filterplugin_action_linksinc\csf\views\welcome.php:20
filterplugin_row_metainc\csf\views\welcome.php:21
actionplugin_loadedshowcase.php:20
actionwp_enqueue_scriptsshowcase.php:45
actionadmin_enqueue_scriptsshowcase.php:55
actioncsf/enqueueshowcase.php:63
actioninitshowcase.php:395
filterpost_row_actionsshowcase.php:414
actionadmin_head-post.phpshowcase.php:431
actionadmin_head-post-new.phpshowcase.php:432
filterpost_updated_messagesshowcase.php:442
filtergettextshowcase.php:447
filteradmin_footer_textshowcase.php:461
filtermanage_bpbs-showcase_posts_columnsshowcase.php:475
actionmanage_bpbs-showcase_posts_custom_columnshowcase.php:476
actionedit_form_after_titleshowcase.php:494
actionadmin_initshowcase.php:511
Maintenance & Trust

Showcase It – Display Projects, Products, or Media in Grid or Slider Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Showcase It – Display Projects, Products, or Media in Grid or Slider Developer Profile

colorlibplugins

120 plugins · 738K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
140 days
View full developer profile
Detection Fingerprints

How We Detect Showcase It – Display Projects, Products, or Media in Grid or Slider

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/showcase-it/public/js/showcase-two.js/wp-content/plugins/showcase-it/public/css/showcase-style-two.css/wp-content/plugins/showcase-it/public/css/showcase-style-three.css/wp-content/plugins/showcase-it/public/css/movie-style.css/wp-content/plugins/showcase-it/public/css/all.min.css/wp-content/plugins/showcase-it/public/css/admin-style.css/wp-content/plugins/showcase-it/admin/ads/style.css
Script Paths
/wp-content/plugins/showcase-it/public/js/showcase-two.js
Version Parameters
/wp-content/plugins/showcase-it/public/css/showcase-style-two.css?ver=1.0.4/wp-content/plugins/showcase-it/public/css/showcase-style-three.css?ver=1.0.4

HTML / DOM Fingerprints

CSS Classes
bk-bookbook-1bk-bookdefaultbk-frontbk-cover-backbk-coverbk-pagebk-content+11 more
Data Attributes
id="bk-list"class="bk-list align clearfix"id="bookclass="bk-book book-1 bk-bookdefault"class="bk-front"class="bk-cover-back"+15 more
Shortcode Output
<div class="container"> <div class="main"> <ul id="bk-list" class="bk-list align clearfix"> <li> <div id="" class="bk-book book-1 bk-bookdefault"> <div class="bk-front"> <div class="bk-cover-back"></div> <div class="bk-cover"> <h2> <span></span> <span>
FAQ

Frequently Asked Questions about Showcase It – Display Projects, Products, or Media in Grid or Slider