
Supafolio Security & Risk Analysis
wordpress.org/plugins/supapressQuickly and easily connect your book metadata (ONIX) to your WordPress site.
Is Supafolio Safe to Use in 2026?
Generally Safe
Score 100/100Supafolio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Supapress plugin, version 2.27.0, exhibits a mixed security posture. While it has no recorded historical vulnerabilities and no critical issues in taint analysis, significant concerns arise from its attack surface. A large number of AJAX handlers (11 out of 11) lack proper authentication checks, presenting a substantial risk of unauthorized actions. The code analysis also reveals issues with output escaping, with only 18% of outputs being properly escaped, increasing the potential for cross-site scripting (XSS) vulnerabilities. The presence of bundled libraries like Select2 and Guzzle v1.1, while not explicitly flagged as outdated, warrants caution as outdated dependencies can introduce known vulnerabilities. Despite a lack of historical CVEs suggesting a proactive approach to security or a low profile, the current static analysis points to immediate risks that need to be addressed, particularly the unprotected AJAX endpoints and widespread output escaping deficiencies.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- SQL queries not always prepared
- Bundled outdated library (Guzzle v1.1)
Supafolio Security Vulnerabilities
Supafolio Release Timeline
Supafolio Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Supafolio Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 28
Maintenance & Trust
Supafolio Maintenance & Trust
Maintenance Signals
Community Trust
Supafolio Alternatives
Kitab
kitab
Kitab - Books Management System for WordPress
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Visual Portfolio, Photo Gallery & Post Grid
visual-portfolio
Powerful WordPress gallery plugin for stunning photo, video & album galleries with advanced layouts and flexible block editing.
Portfolio Post Type
portfolio-post-type
This plugin registers a custom post type for portfolio items. It also registers separate portfolio taxonomies for tags and categories.
Premium Portfolio Features for Phlox theme
auxin-portfolio
Showcase your projects beautifully in Phlox theme
Supafolio Developer Profile
1 plugin · 100 total installs
How We Detect Supafolio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/supapress/admin/css/admin-overrides.min.css/wp-content/plugins/supapress/admin/css/select2.min.css/wp-content/plugins/supapress/admin/js/select2.min.js/wp-content/plugins/supapress/admin/js/add-shortcode.min.js/wp-content/plugins/supapress/admin/css/add-shortcode.min.css/wp-content/plugins/supapress/admin/css/jquery.asmselect.css/wp-content/plugins/supapress/admin/css/styles.min.css/wp-content/plugins/supapress/admin/js/svg4everybody.min.js+4 more/wp-content/plugins/supapress/admin/js/select2.min.js/wp-content/plugins/supapress/admin/js/add-shortcode.min.js/wp-content/plugins/supapress/admin/js/svg4everybody.min.js/wp-content/plugins/supapress/admin/js/jquery.placeholder.min.js/wp-content/plugins/supapress/admin/js/jquery.asmselect.js/wp-content/plugins/supapress/admin/js/scripts.min.js+1 moresupapress-admin-overridessupapress-admin-select2supapress-admin-select2supapress-admin-add-shortcodesupapress-admin-add-shortcodesupapress-admin-asmsupapress-adminsupapress-admin-svg4everybodysupapress-admin-placeholdersupapress-admin-asmsupapress-adminwidgetHTML / DOM Fingerprints
supapresssupafolioThis program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; version 2 of the License.
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU General Public License for more details.
* You should have received a copy of the GNU General Public License
* along with this program; if not, write to the Free Software
* Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USAdata-supapress-setting-idSUPAPRESS_VERSIONSUPAPRESS_SITE_URLSUPAPRESS_PLUGIN_BASENAMESUPAPRESS_PLUGIN_DIRSUPAPRESS_PLUGIN_URLSUPAPRESS_DEFAULT_SERVICE_URL+21 more