Venngage Infographics Security & Risk Analysis

wordpress.org/plugins/venngage

Create and embed your Venngage infographics, charts and data visualizations into your WordPress site

100 active installs v1.0.0 PHP + WP 3.8+ Updated Aug 21, 2015
chartsdata-visualizationinfographicinfographicsvenngage
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Venngage Infographics Safe to Use in 2026?

Generally Safe

Score 85/100

Venngage Infographics has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The Venngage plugin v1.0.0 presents a generally positive security posture based on the provided static analysis. It demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no known vulnerabilities in its history. The limited attack surface, with only one shortcode and no unprotected entry points, is also a strength. However, there are areas for concern, particularly regarding output escaping. With only 27% of outputs properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The absence of nonce checks on the single shortcode, while not directly flagged as an entry point, could potentially be exploited in conjunction with other factors to lead to Cross-Site Request Forgery (CSRF) if the shortcode performs sensitive actions. The presence of bundled libraries like TinyMCE also warrants attention, as outdated versions can introduce security risks if not maintained.

Key Concerns

  • Low output escaping (27%)
  • No nonce checks on shortcode
  • Bundled library (TinyMCE)
Vulnerabilities
None known

Venngage Infographics Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Venngage Infographics Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
3 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

27% escaped11 total outputs
Attack Surface

Venngage Infographics Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[infographic] venngage.php:62
WordPress Hooks 10
actioninitvenngage.php:56
actionwp_enqueue_scriptsvenngage.php:59
actionplugins_loadedvenngage.php:60
actionplugins_loadedvenngage.php:61
actionadmin_enqueue_scriptsvenngage.php:64
actionadmin_initvenngage.php:65
actionsave_postvenngage.php:66
filtermce_external_pluginsvenngage.php:128
filtermce_buttonsvenngage.php:129
filtermce_cssvenngage.php:130
Maintenance & Trust

Venngage Infographics Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedAug 21, 2015
PHP min version
Downloads7K

Community Trust

Rating74/100
Number of ratings3
Active installs100
Developer Profile

Venngage Infographics Developer Profile

venngage

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Venngage Infographics

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/venngage/resources/css/vi.css/wp-content/plugins/venngage/resources/js/vi.js
Script Paths
/wp-content/plugins/venngage/resources/js/shortcode-tinymce-button.js/wp-content/plugins/venngage/resources/js/shortcode-tinymce-button-3.8.js

HTML / DOM Fingerprints

Data Attributes
venngageshortcode
JS Globals
window.__venngage_infographics_plugin_slug__window.__venngage_infographics_version__window.__venngage_infographics_dir__window.__venngage_infographics_url__window.__venngage_infographics_root__window.__venngage_infographics_resources__+5 more
REST Endpoints
/wp-json/__venngage_/
Shortcode Output
[infographic
FAQ

Frequently Asked Questions about Venngage Infographics