
Site Demo Creator Security & Risk Analysis
wordpress.org/plugins/site-demoBrowse and record your site in a browser or mobile mockup, for making site demos, explainer videos, or walk-throughs.
Is Site Demo Creator Safe to Use in 2026?
Generally Safe
Score 85/100Site Demo Creator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "site-demo" plugin v0.0.1 exhibits a generally strong security posture based on the static analysis. There are no identified dangerous functions, all SQL queries are properly prepared, and a high percentage of output is correctly escaped. The plugin also avoids file operations and external HTTP requests, and it has a complete absence of known vulnerabilities in its history. This suggests a developer who is mindful of common security pitfalls.
However, the static analysis also reveals a notable absence of critical security checks. Specifically, there are no detected capability checks, nonce checks, or authentication checks on any of the identified entry points, which are zero in number. While the attack surface is currently minimal, any future expansion of functionality without incorporating these essential security mechanisms could introduce significant risks. The lack of taint analysis flows also makes it impossible to assess the handling of potentially untrusted data.
In conclusion, the plugin demonstrates good practices in core coding principles like output escaping and secure database interaction. The primary weakness lies in the apparent lack of fundamental security controls for authentication and authorization on its (currently non-existent) entry points. While this is not an immediate critical risk due to the limited attack surface, it represents a significant area for improvement to ensure future security as the plugin evolves.
Key Concerns
- No capability checks on entry points
- No nonce checks on entry points
- No AJAX auth checks
- No REST API permission callbacks
- No taint analysis data provided
Site Demo Creator Security Vulnerabilities
Site Demo Creator Release Timeline
Site Demo Creator Code Analysis
Output Escaping
Site Demo Creator Attack Surface
WordPress Hooks 3
Maintenance & Trust
Site Demo Creator Maintenance & Trust
Maintenance Signals
Community Trust
Site Demo Creator Alternatives
WP Links Page
wp-links-page
This plugin allows you to create a dynamic link gallery with screenshots of each link.
Browser Screenshots
browser-shots
Automate the process of taking website screenshots.
CopySafe Web Protection – Copy Protect Images
wp-copysafe-web
Copy protect images and web pages. Add encrypted images to copy protect pages from PrintScreen and screen capture.
Usersnap
usersnap
Usersnap: The feedback platform designed to capture, organize, and respond to user feedback seamlessly.
Theme Preview
theme-preview
Allows you test how a theme looks on your site without activating it.
Site Demo Creator Developer Profile
2 plugins · 40 total installs
How We Detect Site Demo Creator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/site-demo/templates/browser.php/wp-content/plugins/site-demo/templates/mobile.phpHTML / DOM Fingerprints
header-circlesheader-inputid="browser"id="header"id="header-circles"id="header-input"id="url"id="iframe"+2 moreurliframemaybeUpdateUrl