
The Joshua Project, Daily Unreached People Widget Security & Risk Analysis
wordpress.org/plugins/the-joshua-project-daily-unreached-people-widgetCreates a widget highlighting a people group unreached with the Gospel of Christ.
Is The Joshua Project, Daily Unreached People Widget Safe to Use in 2026?
Generally Safe
Score 85/100The Joshua Project, Daily Unreached People Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "the-joshua-project-daily-unreached-people-widget" v1.0 demonstrates a strong security posture in several key areas. The static analysis reveals a remarkably small attack surface with zero AJAX handlers, REST API routes, shortcodes, or cron events identified. Furthermore, there are no dangerous functions, file operations, or external HTTP requests that immediately raise red flags, and all SQL queries utilize prepared statements. The high percentage of properly escaped output also suggests good practices for preventing cross-site scripting vulnerabilities.
However, there are notable areas of concern that detract from its overall security. The complete absence of nonce checks and capability checks across all identified entry points (even if there are none) indicates a lack of fundamental security controls that would typically be expected, even for plugins with minimal exposed functionality. While taint analysis found no issues, the lack of analysis itself is a weakness if the tool has limitations or the plugin's logic is complex. The plugin also makes one external HTTP request, which, while not inherently dangerous, warrants scrutiny to ensure it's secure and doesn't expose the site to risks.
Given the plugin's perfect record with zero recorded vulnerabilities and CVEs, it suggests that it has either been remarkably secure or has not been subjected to significant scrutiny. However, the lack of basic security checks like nonces and capability checks in its code presents a significant latent risk. A well-resourced attacker could potentially leverage any future unauthenticated entry points or flaws in the external HTTP request to compromise the site. While the current state is promising, the reliance on a lack of discovered vulnerabilities rather than proactive security measures is a weakness.
Key Concerns
- No nonce checks on any entry points
- No capability checks on any entry points
- One external HTTP request
- Limited taint analysis (0 flows analyzed)
The Joshua Project, Daily Unreached People Widget Security Vulnerabilities
The Joshua Project, Daily Unreached People Widget Code Analysis
Output Escaping
The Joshua Project, Daily Unreached People Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
The Joshua Project, Daily Unreached People Widget Maintenance & Trust
Maintenance Signals
Community Trust
The Joshua Project, Daily Unreached People Widget Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
The Joshua Project, Daily Unreached People Widget Developer Profile
10 plugins · 190 total installs
How We Detect The Joshua Project, Daily Unreached People Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_joshua-project-daily-unreached-widgetimagepopulationlanguagereligionstatusdata-iddata-namedata-description