
Simple Blog Card Security & Risk Analysis
wordpress.org/plugins/simple-blog-cardGet OGP and display blog card.
Is Simple Blog Card Safe to Use in 2026?
Generally Safe
Score 99/100Simple Blog Card has a strong security track record. Known vulnerabilities have been patched promptly.
The "simple-blog-card" v2.38 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a clean attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, indicating a minimal footprint for potential exploitation. Furthermore, all output appears to be properly escaped, and there are no file operations or external HTTP requests, which are excellent security practices. The absence of any critical or high-severity taint flows is also a strong positive. However, significant concerns arise from the vulnerability history. The plugin has a history of two medium-severity vulnerabilities, specifically Exposure of Sensitive Information and Cross-site Scripting, with the last one occurring in August 2023. While currently unpatched CVEs are zero, this history suggests a pattern of introducing vulnerabilities that require remediation. The fact that SQL queries are not using prepared statements is a notable weakness, as it could lead to SQL injection vulnerabilities if the input is not rigorously sanitized, despite the lack of identified taint flows in this specific analysis.
In conclusion, while the current version of "simple-blog-card" appears to have a small attack surface and good output escaping, its past vulnerability record and the use of raw SQL queries are significant red flags. The absence of any capability checks or nonce checks, combined with the past medium-severity CVEs, means that users should exercise caution. The plugin developers have demonstrated an ability to introduce security flaws, and the reliance on raw SQL without prepared statements is a fundamental security risk that should be addressed. Continued monitoring and prompt patching of any new vulnerabilities are crucial for users of this plugin.
Key Concerns
- Raw SQL queries without prepared statements
- History of 2 medium severity CVEs
- No nonce checks implemented
- No capability checks implemented
Simple Blog Card Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Simple Blog Card <= 1.31 - Sensitive Information Exposure
Simple Blog Card <= 1.30 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Simple Blog Card Code Analysis
SQL Query Safety
Output Escaping
Simple Blog Card Attack Surface
Maintenance & Trust
Simple Blog Card Maintenance & Trust
Maintenance Signals
Community Trust
Simple Blog Card Alternatives
Pz-LinkCard
pz-linkcard
This plugin is intended to display a link in a blog card format. The goodbye to the text-only link.
Broken Link Checker
broken-link-checker
Broken Link Checker helps you catch broken links & images fast, before they hurt your SEO or UX. Scan and bulk-fix issues from one easy dashboard.
Broken Link Checker by AIOSEO – Easily Fix/Monitor Internal and External links
broken-link-checker-seo
Broken Link Checker by AIOSEO ensures all links on your website are working. Check your site for broken links and easily fix them to improve SEO.
Pz-HatenaBlogCard
pz-hatenablogcard
This plug-in to display a link in the article by using the "Hatena blog card".
anyLink
anylink
AnyLink is a Wordpress plugin which allow you to customise you external link like an internal one.
Simple Blog Card Developer Profile
52 plugins · 56K total installs
How We Detect Simple Blog Card
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-blog-card/admin/css/style.css/wp-content/plugins/simple-blog-card/admin/js/main.js/wp-content/plugins/simple-blog-card/admin/js/settings.js/wp-content/plugins/simple-blog-card/public/css/style.css/wp-content/plugins/simple-blog-card/public/js/main.js/wp-content/plugins/simple-blog-card/admin/js/main.js/wp-content/plugins/simple-blog-card/admin/js/settings.js/wp-content/plugins/simple-blog-card/public/js/main.jssimple-blog-card/admin/css/style.css?ver=simple-blog-card/admin/js/main.js?ver=simple-blog-card/admin/js/settings.js?ver=simple-blog-card/public/css/style.css?ver=simple-blog-card/public/js/main.js?ver=HTML / DOM Fingerprints
simple-blog-cardsbc-blog-cardsbc-card-imagesbc-card-titlesbc-card-descriptionsbc-card-site-titledata-sbc-urldata-sbc-iddata-sbc-titledata-sbc-descriptiondata-sbc-imagedata-sbc-site-titleSimpleBlogCard[simple_blog_card[/simple_blog_card]