Simple Wp Mixitup Portfolio Security & Risk Analysis

wordpress.org/plugins/simple-wp-mixitup-portfolio

Simple Mixitup Portfolio allows you to create a very modern and outstanding portfolio which filters instantly using jQuery animations.

0 active installs v1.0 PHP + WP 5.0.1+ Updated Jan 7, 2024
awesome-photo-galleyimage-galleryphotosimple-wp-mixitup-portfoliowidget-photo-gallery
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple Wp Mixitup Portfolio Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Wp Mixitup Portfolio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'simple-wp-mixitup-portfolio' plugin v1.0 exhibits a mixed security posture. On the positive side, it has no known vulnerabilities in its history, utilizes prepared statements for all SQL queries, and has no file operations or external HTTP requests. This suggests a developer who is mindful of common plugin security pitfalls.

However, significant concerns arise from the static analysis. The plugin has 100% of its outputs unescaped, which is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities. Furthermore, there are no explicit nonce or capability checks evident in the provided analysis, and the plugin has a single entry point via a shortcode. While the attack surface is small and currently has no unprotected entry points, the absence of nonce and capability checks on the shortcode's execution is a major oversight. The lack of taint analysis flows is not necessarily a positive; it could simply mean the analysis tool did not find any exploitable patterns within the limited scope or the plugin's code structure.

Given the complete absence of unescaped output and the lack of nonce/capability checks on its single entry point, the plugin presents a notable risk. The clean vulnerability history is encouraging but does not mitigate the immediate security flaws identified in the code. Developers should prioritize addressing the unescaped output and implementing proper authorization checks for the shortcode to improve the plugin's security.

Key Concerns

  • All outputs are unescaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Simple Wp Mixitup Portfolio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Simple Wp Mixitup Portfolio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

Simple Wp Mixitup Portfolio Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[simple-portfolio] Simple-Wp-Mixitup-Portfolio.php:15
WordPress Hooks 2
actionwp_enqueue_scriptsSimple-Wp-Mixitup-Portfolio.php:13
actioninitSimple-Wp-Mixitup-Portfolio.php:14
Maintenance & Trust

Simple Wp Mixitup Portfolio Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJan 7, 2024
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Simple Wp Mixitup Portfolio Developer Profile

nayon46

12 plugins · 820 total installs

84
trust score
Avg Security Score
86/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Wp Mixitup Portfolio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-wp-mixitup-portfolio/css/portfolio.css/wp-content/plugins/simple-wp-mixitup-portfolio/js/jquery.mixitup.min.js/wp-content/plugins/simple-wp-mixitup-portfolio/js/portfolio.js
Script Paths
/wp-content/plugins/simple-wp-mixitup-portfolio/js/jquery.mixitup.min.js/wp-content/plugins/simple-wp-mixitup-portfolio/js/portfolio.js
Version Parameters
simple-wp-mixitup-portfolio/css/portfolio.css?ver=simple-wp-mixitup-portfolio/js/jquery.mixitup.min.js?ver=simple-wp-mixitup-portfolio/js/portfolio.js?ver=

HTML / DOM Fingerprints

CSS Classes
mixiareamixifiltercontrolsfilterContainerrrcontainerrmax-total-areamix+5 more
HTML Comments
<!-- Portfolio Section Start --><!-- WORK ITEM --><!-- END / WORK ITEM --><!-- Portfolio Section End -->
Data Attributes
data-filterdata-filter
Shortcode Output
<section class="portfolio padding-top"><div class="mixiarea"><div class="mixifilter"><div class="controls">
FAQ

Frequently Asked Questions about Simple Wp Mixitup Portfolio