Untappd WordPress Widget Security & Risk Analysis

wordpress.org/plugins/untappd-checkins-widget

Display recent Untappd Checkins via widget

100 active installs v1.3.3 PHP 5.3+ WP 3.5+ Updated Jul 9, 2020
beersocial-drinkinguntappdwidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Untappd WordPress Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Untappd WordPress Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "untappd-checkins-widget" plugin v1.3.3 exhibits a generally strong security posture, with no reported vulnerabilities or critical code signals. The absence of dangerous functions, SQL queries without prepared statements, and a clean taint analysis are significant strengths. Furthermore, the plugin demonstrates good practice by performing numerous capability checks and a substantial percentage of output escaping, mitigating common attack vectors.

However, a notable concern lies in the 43% of outputs that are not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if untrusted data is rendered directly to the user without adequate sanitization. While the plugin has no recorded vulnerability history, this does not guarantee future immunity, especially given the identified unescaped output.

In conclusion, the plugin is well-developed from a security perspective, with no critical flaws detected. The primary area for improvement and vigilance is ensuring all output is appropriately escaped to prevent potential XSS issues. Continued monitoring for any future vulnerabilities is always recommended.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Untappd WordPress Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Untappd WordPress Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
52 escaped
Nonce Checks
0
Capability Checks
20
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

57% escaped92 total outputs
Attack Surface

Untappd WordPress Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initclasses\class-mb-untappd-settings.php:22
actionadmin_menuclasses\class-mb-untappd-settings.php:23
actionwidgets_inituntappdwidget.php:50
actionplugins_loadeduntappdwidget.php:72
Maintenance & Trust

Untappd WordPress Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJul 9, 2020
PHP min version5.3
Downloads12K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Untappd WordPress Widget Developer Profile

Michael Beckwith

9 plugins · 370 total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Untappd WordPress Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/untappd-checkins-widget/js/untappd.js/wp-content/plugins/untappd-checkins-widget/css/untappd.css
Script Paths
/wp-content/plugins/untappd-checkins-widget/js/untappd.js
Version Parameters
untappd-checkins-widget/js/untappd.js?ver=untappd-checkins-widget/css/untappd.css?ver=

HTML / DOM Fingerprints

CSS Classes
untappd-brewery-checkinsuntappd-user-checkinsuntappd-user-badgesuntappd-venue-checkinsuntappd-user-profilemb_untappd_widget
HTML Comments
<!-- Generated by Untappd Checkins Widget -->
Data Attributes
data-brewery-iddata-user-namedata-venue-iddata-client-iddata-client-secretdata-limit
JS Globals
UntappdCheckins
FAQ

Frequently Asked Questions about Untappd WordPress Widget