
Simple Org Chart Security & Risk Analysis
wordpress.org/plugins/simple-org-chartCreate a simple jQuery Org Chart which will display your team or organisation structure in a hierarchical fashion, using easy drag and drop facilities …
Is Simple Org Chart Safe to Use in 2026?
Generally Safe
Score 99/100Simple Org Chart has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of simple-org-chart v2.3.5 reveals a generally strong security posture. The plugin demonstrates good practices by implementing nonce checks and capability checks on all identified entry points (AJAX handlers, REST API routes, and shortcodes). The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is also a positive sign. Taint analysis shows no critical or high severity unsanitized flows, indicating that user-supplied data is likely being handled safely within the analyzed paths.
However, the plugin's vulnerability history presents a notable concern. With two known medium-severity CVEs in its past, including a recent one from August 2023, it suggests a recurring pattern of security weaknesses. While there are currently no unpatched vulnerabilities, the past incidents, particularly those involving CSRF and missing authorization, indicate potential areas where oversight might have occurred. The presence of these past vulnerabilities, even if resolved, warrants continued vigilance and suggests that the plugin may not have a perfect track record in preventing certain classes of security flaws.
In conclusion, simple-org-chart v2.3.5 exhibits commendable defensive coding practices in its current version. The lack of immediate critical risks from the static analysis is reassuring. Nevertheless, the historical prevalence of medium-severity vulnerabilities, especially those related to authorization and CSRF, should not be overlooked. Users should remain aware of this history and ensure the plugin is always updated to the latest version to benefit from any past security fixes and to mitigate the risk of similar issues recurring.
Key Concerns
- Two past medium severity CVEs
- Recent vulnerability (2023-08-17)
Simple Org Chart Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Simple Org Chart <= 2.3.4 - Cross-Site Request Forgery
Simple Org Chart <= 2.3.4 - Missing Authorization
Simple Org Chart Code Analysis
Output Escaping
Data Flow Analysis
Simple Org Chart Attack Surface
AJAX Handlers 1
REST API Routes 1
Shortcodes 1
WordPress Hooks 21
Maintenance & Trust
Simple Org Chart Maintenance & Trust
Maintenance Signals
Community Trust
Simple Org Chart Alternatives
Organization chart
organization-chart
WordPress organization chart plugin is a nice and handy tool for creating simple and nice organizational charts. If you have any suggestions about the …
Clicface Organi
clicface-organi
Create Org Charts easily in WordPress. A flexible and lightweight WordPress plugin, working with Clicface Trombi.
Interactive Organizational Chart
interactive-organizational-chart
A complete WordPress plugin for managing and displaying interactive organizational charts with admin and editor data upload and user-friendly viewing.
Simple Org Chart Developer Profile
4 plugins · 2K total installs
How We Detect Simple Org Chart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-org-chart/css/jquery.jOrgChart.css/wp-content/plugins/simple-org-chart/css/custom.css/wp-content/plugins/simple-org-chart/js/jquery.jOrgChart.js/wp-content/plugins/simple-org-chart/js/custom.js/wp-content/plugins/simple-org-chart/js/jquery.jOrgChart.js/wp-content/plugins/simple-org-chart/js/custom.jssimple-org-chart/js/custom.js?ver=2.3.5HTML / DOM Fingerprints
orgchartoblockoinlineoverlay1popup1close1data-id="bioorgChartAjax[orgchart]