
LAPDI Facepile Security & Risk Analysis
wordpress.org/plugins/tsp-facepileFacepile allows you to add WordPress users photo icons to your blog's website in grid format.
Is LAPDI Facepile Safe to Use in 2026?
Generally Safe
Score 85/100LAPDI Facepile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tsp-facepile plugin v1.1.6 presents a generally good security posture with no identified vulnerabilities in its history and a limited attack surface. The static analysis reveals no critical findings such as dangerous functions, file operations, or external HTTP requests. Taint analysis also shows no concerning flows. However, there are areas for improvement that slightly detract from an otherwise positive assessment. Specifically, the plugin's handling of SQL queries and output escaping raises concerns. While some SQL queries are prepared, a significant portion are not, and critically, none of the identified output operations are properly escaped. This lack of output escaping could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever incorporated into the plugin's output. The presence of a nonce check and a capability check for the shortcode are positive indicators of security awareness, but the absence of capability checks on other potential entry points like AJAX and REST API routes (though currently zero) is a minor weakness. Given the absence of known vulnerabilities and critical static analysis findings, the overall risk is currently low, but the unescaped output and partial SQL preparation warrant attention.
Key Concerns
- Output escaping: 0% properly escaped
- SQL queries: 50% not using prepared statements
- Capability checks: 0 on entry points
LAPDI Facepile Security Vulnerabilities
LAPDI Facepile Code Analysis
SQL Query Safety
Output Escaping
LAPDI Facepile Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
LAPDI Facepile Maintenance & Trust
Maintenance Signals
Community Trust
LAPDI Facepile Alternatives
Grid/List View for WooCommerce
gridlist-view-for-woocommerce
Simple plugin for WooCommerce which toggle grid / list view of your products and toggle products count per page.
RealHomes Memberships
inspiry-memberships
Membership packages plugin for RealHomes Real Estate theme only.
Plugins List
plugins-list
Allows you to insert a list of the Wordpress plugins you are using into any post/page.
Easy HTML Sitemap
easy-html-sitemap
Easy HTML Sitemap - Display an HTML Sitemap for your wordpress pages using a shortcode. The sitemap is updated in realtime.
Fake Who’s Online for WordPress
fake-whos-online-widget
Fake whos online is a plugin that allows you to make your site seem more popular by displaying a fake amount of users online on your Wordpress site.
LAPDI Facepile Developer Profile
7 plugins · 220 total installs
How We Detect LAPDI Facepile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tsp-facepile/tsp-facepile.cssHTML / DOM Fingerprints
tsp-facepiletsp-facepile-nonce-name