
Vernissaria QR Security & Risk Analysis
wordpress.org/plugins/vernissaria-qrGenerate QR codes for artworks and track visitor engagement with detailed analytics.
Is Vernissaria QR Safe to Use in 2026?
Generally Safe
Score 100/100Vernissaria QR has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "vernissaria-qr" plugin v1.3.6 presents a mixed security posture. On the positive side, there are no known historical vulnerabilities (CVEs), and the static analysis shows a well-defined attack surface with all identified entry points (AJAX handlers and shortcodes) appearing to have authentication checks. The presence of capability checks and nonces further bolsters this. However, significant concerns arise from the code signals. The plugin uses raw SQL queries for all its database interactions, which is a major security risk, especially if the data originates from user input. Additionally, a substantial portion of output escaping is missing, potentially leading to cross-site scripting (XSS) vulnerabilities. The taint analysis, while not reporting critical or high severity flows, did find unsanitized paths, which, when combined with the lack of prepared statements and insufficient output escaping, could still lead to exploitable conditions.
Key Concerns
- All SQL queries lack prepared statements
- Nearly half of output escaping is missing
- Taint analysis shows unsanitized paths
Vernissaria QR Security Vulnerabilities
Vernissaria QR Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Vernissaria QR Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
Vernissaria QR Maintenance & Trust
Maintenance Signals
Community Trust
Vernissaria QR Alternatives
Web Worker Offloading
web-worker-offloading
Offloads select JavaScript execution to a Web Worker to reduce work on the main thread and improve the Interaction to Next Paint (INP) metric.
Chartbeat
chartbeat
The Chartbeat plugin automatically adds real-time data and a top pages widget to your blog. See who’s on your site, what they’re doing - right now
core plugin for kitestudio themes
kitestudio-core
Useful plugin that extends functionality of Kitestudio Themes by adding woocommerce shortcodes and widgets
NGG Smart Image Search
ngg-smart-image-search
NGG Smart Image Search provides a smart search and display functionality for images in selectable arbitary collections of NextGEN galleries.
Cart tracking for WooCommerce
cart-tracking-for-woocommerce
Keep track of what people are adding or removing from their cart. See most added/removed products lists.
Vernissaria QR Developer Profile
2 plugins · 0 total installs
How We Detect Vernissaria QR
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/vernissaria-qr/assets/css/admin.css/wp-content/plugins/vernissaria-qr/assets/js/metabox.js/wp-content/plugins/vernissaria-qr/assets/js/metabox.jsvernissaria-qr/assets/css/admin.css?ver=vernissaria-qr/assets/js/metabox.js?ver=HTML / DOM Fingerprints
<!-- Generated by Vernissaria QR --><!-- QR Code Image --><!-- QR Code Link --><!-- QR Code Scan Count -->+4 moredata-qr-code-redirect-keydata-qr-code-urldata-qr-code-labeldata-qr-code-campaigndata-qr-code-dimensionsdata-qr-code-yearvernissariaMetabox/wp-json/vernissaria-qr/v1/generate-qr/wp-json/vernissaria-qr/v1/update-qr/wp-json/vernissaria-qr/v1/delete-qr[vernissaria_qr_code][vernissaria_qr_details]