SV Proven Expert Security & Risk Analysis

wordpress.org/plugins/sv-provenexpert

Show Review Stars via ProvenExpert.com in WordPress

1K active installs v2.0.06 PHP 8.0+ WP 6.0.0+ Updated Jul 18, 2024
google-star-reviewsproven-expertprovenexpertreviewsstraightvisions
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 22, 2025
Safety Verdict

Is SV Proven Expert Safe to Use in 2026?

Mostly Safe

Score 70/100

SV Proven Expert is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Sep 22, 2025Updated 1yr ago
Risk Assessment

The "sv-provenexpert" plugin v2.0.06 exhibits a mixed security posture. On the positive side, the static analysis reveals a clean codebase with no identified dangerous functions, file operations, or external HTTP requests. Importantly, all SQL queries are prepared, and output is consistently escaped, which are strong indicators of good secure coding practices in these areas. There are also no identified vulnerabilities in taint analysis.

However, significant concerns arise from the vulnerability history. The presence of one unpatched medium-severity CVE, historically associated with Cross-Site Request Forgery (CSRF), indicates a past weakness that has not been remediated. The lack of any explicit capability checks or nonce checks in the static analysis is also a red flag, especially considering the common vulnerability type and the potential for unauthenticated or improperly authenticated actions if the plugin's functionality relies on such checks that weren't detected or were implemented inadequately.

In conclusion, while the current codebase appears robust against common static analysis threats like SQL injection and XSS through proper escaping and prepared statements, the unpatched historical vulnerability and the absence of explicit security checks in the static analysis create an unacceptable risk. The plugin has demonstrated a past susceptibility to CSRF, and without clear evidence of mitigation for this and other potential unauthorized actions, its overall security remains questionable, especially for a plugin that might handle sensitive data or user interactions.

Key Concerns

  • Unpatched medium vulnerability (CVE)
  • No capability checks found
  • No nonce checks found
Vulnerabilities
1

SV Proven Expert Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-58010medium · 4.3Cross-Site Request Forgery (CSRF)

SV Proven Expert <= 2.0.06 - Cross-Site Request Forgery

Sep 22, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

SV Proven Expert Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

SV Proven Expert Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

SV Proven Expert Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 18, 2024
PHP min version8.0
Downloads23K

Community Trust

Rating76/100
Number of ratings5
Active installs1K
Developer Profile

SV Proven Expert Developer Profile

straightvisions GmbH

8 plugins · 2K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SV Proven Expert

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sv-provenexpert/assets/css/style.css/wp-content/plugins/sv-provenexpert/assets/js/script.js/wp-content/plugins/sv-provenexpert/lib/core_plugin/dependencies/sv_dependencies.js
Script Paths
/wp-content/plugins/sv-provenexpert/assets/js/script.js/wp-content/plugins/sv-provenexpert/lib/core_plugin/dependencies/sv_dependencies.js
Version Parameters
sv-provenexpert/assets/css/style.css?ver=sv-provenexpert/assets/js/script.js?ver=sv-provenexpert/lib/core_plugin/dependencies/sv_dependencies.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about SV Proven Expert