
Sweet Glossary Security & Risk Analysis
wordpress.org/plugins/sweet-glossaryA simple, beautiful and SEO friendly glossary plugin. Place the shortcode wherever you want and display the list of glossary terms wherever you want.
Is Sweet Glossary Safe to Use in 2026?
Generally Safe
Score 85/100Sweet Glossary has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sweet-glossary" v1.0.0 plugin demonstrates a generally strong security posture due to its adherence to several best practices. Notably, all SQL queries are prepared, all identified output is properly escaped, and there are no dangerous functions, file operations, or external HTTP requests. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a history of secure development or diligent maintenance. However, several areas of concern exist. The absence of nonce checks and capability checks across all entry points, particularly the single shortcode, is a significant weakness. While the static analysis did not identify any unescaped user input in taint flows, the fact that two flows with unsanitized paths were found warrants attention, even if they did not reach a critical or high severity in this analysis. The combination of a shortcode as an entry point without any authentication or authorization checks creates a potential avenue for attack.
In conclusion, while the plugin benefits from secure coding practices like prepared statements and output escaping, the lack of input validation and authorization mechanisms on its shortcode represents a substantial risk. The fact that taint analysis flagged unsanitized paths, even without critical severity, should not be overlooked. Future versions should prioritize implementing nonce and capability checks to mitigate potential vulnerabilities that could arise from these oversight.
Key Concerns
- Missing nonce check for entry points
- Missing capability check for entry points
- Taint flow with unsanitized paths
Sweet Glossary Security Vulnerabilities
Sweet Glossary Release Timeline
Sweet Glossary Code Analysis
Output Escaping
Data Flow Analysis
Sweet Glossary Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Sweet Glossary Maintenance & Trust
Maintenance Signals
Community Trust
Sweet Glossary Alternatives
Do Shortcodes for Rank Math SEO
do-shortcodes-for-rank-math-seo
Display shortcodes in the title, description, Facebook and Twitter fields, and other locations for Rank Math SEO.
Term Description Popup
term-description-popup
This plugin displays a keyword description in a popup whenever a term in the text of a post or page matches that keyword.
Yoast SEO – Advanced SEO with real-time guidance and built-in AI
wordpress-seo
Improve your SEO with real-time feedback, schema, and clear guidance. Upgrade for AI tools, Google Docs integration, and 24/7 support, no hidden fees.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Rank Math SEO – AI SEO Tools to Dominate SEO Rankings
seo-by-rank-math
Rank Math SEO is the best WordPress SEO plugin with the features of many SEO and AI SEO tools in a single package to help multiply your SEO traffic.
Sweet Glossary Developer Profile
2 plugins · 10 total installs
How We Detect Sweet Glossary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sweet-glossary/css/sweet-glossary-admin.css/wp-content/plugins/sweet-glossary/js/sweet-glossary-admin.js/wp-content/plugins/sweet-glossary/js/sweet-glossary-admin.jssweet-glossary-admin.css?ver=sweet-glossary-admin.js?ver=HTML / DOM Fingerprints
setting-examplename="sweet-glossary_slug"id="sweet-glossary_slug"