Simplebooklet PDF Viewer and Embedder Security & Risk Analysis

wordpress.org/plugins/simplebooklet

Add a flip booklet onto your wordpress page.

600 active installs v1.1.4 PHP + WP 3.0+ Updated Mar 18, 2025
bookletflip-bookpdfpdf-viewersimplebooklet
91
A · Safe
CVEs total2
Unpatched0
Last CVEMar 27, 2025
Safety Verdict

Is Simplebooklet PDF Viewer and Embedder Safe to Use in 2026?

Generally Safe

Score 91/100

Simplebooklet PDF Viewer and Embedder has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Mar 27, 2025Updated 1yr ago
Risk Assessment

The static analysis of simplebooklet v1.1.4 reveals a generally good security posture in terms of common coding practices. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The attack surface is minimal, with only one shortcode and no unprotected entry points. Furthermore, the absence of file operations, external HTTP requests, and reported taint flows suggests robust input validation and sanitization.

However, the vulnerability history presents a significant concern. The plugin has a record of two medium-severity CVEs, both related to Cross-Site Scripting (XSS). While these are currently patched, the recurring nature of XSS vulnerabilities in the plugin's past indicates a potential weakness in how user-generated content or external data is handled, which could resurface if not rigorously addressed.

In conclusion, while the current version of simplebooklet v1.1.4 demonstrates strong adherence to secure coding principles based on static analysis, its historical vulnerability pattern warrants attention. The past prevalence of XSS issues suggests a need for ongoing vigilance and comprehensive security testing to ensure new vulnerabilities are not introduced, especially in areas interacting with user input.

Key Concerns

  • Medium severity CVEs in history
  • Past XSS vulnerability type
  • No nonce checks identified
  • No capability checks identified
Vulnerabilities
2

Simplebooklet PDF Viewer and Embedder Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-30922medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simplebooklet PDF Viewer and Embedder <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 27, 2025 Patched in 1.1.3 (7d)
CVE-2024-13588medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simplebooklet PDF Viewer and Embedder <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 17, 2025 Patched in 1.1.3 (3d)
Code Analysis
Analyzed Mar 16, 2026

Simplebooklet PDF Viewer and Embedder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

Simplebooklet PDF Viewer and Embedder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[simplebooklet] simplebooklet.php:72
WordPress Hooks 1
actionwp_enqueue_scriptssimplebooklet.php:30
Maintenance & Trust

Simplebooklet PDF Viewer and Embedder Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 18, 2025
PHP min version
Downloads12K

Community Trust

Rating60/100
Number of ratings1
Active installs600
Developer Profile

Simplebooklet PDF Viewer and Embedder Developer Profile

simplebooklet

1 plugin · 600 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect Simplebooklet PDF Viewer and Embedder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
simplebooklet_iframe
HTML Comments
simplebooklet plugin v.1.1.2 (wordpress.org/extend/plugins/simplebooklet/)
Data Attributes
widthheightsrc
Shortcode Output
<iframe class="simplebooklet_iframe" scrolling="no" frameborder="0" style="border: 0px; overflow: hidden; width: px; height: px;" src="
FAQ

Frequently Asked Questions about Simplebooklet PDF Viewer and Embedder