Vcgs Toolbox Security & Risk Analysis

wordpress.org/plugins/vcgs-toolbox

Very simple plugin that includes some awesome options, features, shortcodes and scripts for improve your blogging experience.

100 active installs v1.9.32 PHP + WP 3.9+ Updated Dec 21, 2017
analyticsiconstoolstweet-thistwitter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vcgs Toolbox Safe to Use in 2026?

Generally Safe

Score 85/100

Vcgs Toolbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The vcgs-toolbox plugin v1.9.32 exhibits a mixed security posture. While it has a clean vulnerability history with no recorded CVEs, indicating a history of good security practices, the static analysis reveals several areas of concern. A significant risk is the presence of an unprotected AJAX handler, representing a direct entry point for potential unauthenticated attacks. Additionally, the plugin uses the dangerous `unserialize` function, which, if coupled with unsanitized input, could lead to Remote Code Execution vulnerabilities. The taint analysis further highlights two high-severity flows with unsanitized paths, suggesting potential injection vulnerabilities that could be exploited if user-controlled data is not properly validated and sanitized before being used in sensitive operations. Despite these concerning findings, the plugin does show some good practices, such as the use of prepared statements for most SQL queries and a reasonable number of nonce checks. However, the low percentage of properly escaped output (21%) is a significant weakness, leaving the plugin susceptible to Cross-Site Scripting (XSS) attacks.

Key Concerns

  • AJAX handler without authentication
  • High severity unsanitized taint flows
  • Dangerous unserialize function
  • Low percentage of properly escaped output
  • Bundled outdated Select2 library v3.4.6
Vulnerabilities
None known

Vcgs Toolbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Vcgs Toolbox Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
3 prepared
Unescaped Output
87
23 escaped
Nonce Checks
8
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
1

Dangerous Functions Found

unserialize$import_code = unserialize($import_code);admin-page-class\admin-page-class.php:3325

Bundled Libraries

Select23.4.6

SQL Query Safety

75% prepared4 total queries

Output Escaping

21% escaped110 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
import (admin-page-class\admin-page-class.php:3313)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Vcgs Toolbox Attack Surface

Entry Points7
Unprotected1

AJAX Handlers 5

authwp_ajax_apc_delete_muploadadmin-page-class\admin-page-class.php:308
authwp_ajax_plupload_actionadmin-page-class\admin-page-class.php:314
authwp_ajax_at_delete_fileadmin-page-class\admin-page-class.php:1095
authwp_ajax_at_reorder_imagesadmin-page-class\admin-page-class.php:1096
authwp_ajax_at_delete_muploadadmin-page-class\admin-page-class.php:1098

Shortcodes 2

[piopialo] vcgs-toolbox.php:258
[midenlace] vcgs-toolbox.php:413
WordPress Hooks 39
actiontemplate_redirectadmin-page-class\admin-page-class.php:209
filterinitadmin-page-class\admin-page-class.php:210
actionadmin_menuadmin-page-class\admin-page-class.php:274
actionadmin_menuadmin-page-class\admin-page-class.php:278
filterattribute_escapeadmin-page-class\admin-page-class.php:305
actionadmin_print_stylesadmin-page-class\admin-page-class.php:376
actionpost_edit_form_tagadmin-page-class\admin-page-class.php:1075
filtermedia_upload_galleryadmin-page-class\admin-page-class.php:1090
filtermedia_upload_libraryadmin-page-class\admin-page-class.php:1091
filtermedia_upload_imageadmin-page-class\admin-page-class.php:1092
filtermanage_edit-post_columnscolumna-contapalabras.php:3
actionmanage_posts_custom_columncolumna-contapalabras.php:10
actioncomment_postcomentarios-pendientes.php:65
actioncomment_postcomentarios-pendientes.php:66
actionpre_get_commentscomentarios-pendientes.php:69
filtermanage_edit-comments_columnscomentarios-pendientes.php:73
filtermanage_comments_custom_columncomentarios-pendientes.php:74
filtercomment_status_linkscomentarios-pendientes.php:77
actionadmin_headcomentarios-pendientes.php:80
actionplugins_loadedcomentarios-pendientes.php:473
actionwp_enqueue_scriptsvcgs-toolbox.php:63
actionwp_enqueue_scriptsvcgs-toolbox.php:77
actionwp_enqueue_scriptsvcgs-toolbox.php:89
actionwp_enqueue_scriptsvcgs-toolbox.php:98
actionwp_enqueue_scriptsvcgs-toolbox.php:106
actioninitvcgs-toolbox.php:261
filtermce_external_pluginsvcgs-toolbox.php:263
filtermce_buttonsvcgs-toolbox.php:264
filterthe_contentvcgs-toolbox.php:279
filtercomment_textvcgs-toolbox.php:293
actionwp_headvcgs-toolbox.php:342
filtercomment_textvcgs-toolbox.php:350
actionwp_enqueue_scriptsvcgs-toolbox.php:389
filterthe_excerpt_rssvcgs-toolbox.php:427
filterthe_content_feedvcgs-toolbox.php:428
filtercomment_post_redirectvcgs-toolbox.php:432
filtercomment_form_defaultsvcgs-toolbox.php:452
filtercomment_form_field_commentvcgs-toolbox.php:455
actioncomment_form_topvcgs-toolbox.php:458
Maintenance & Trust

Vcgs Toolbox Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 21, 2017
PHP min version
Downloads11K

Community Trust

Rating100/100
Number of ratings10
Active installs100
Developer Profile

Vcgs Toolbox Developer Profile

Victor Campuzano

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vcgs Toolbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Vcgs Toolbox