Viralism Security & Risk Analysis

wordpress.org/plugins/viralism

Fetch Viral videos/images and create automated post.

10 active installs v1.0.0 PHP + WP 4.2+ Updated Jun 6, 2017
flickrpinterestvimeoviralismyoutube
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Viralism Safe to Use in 2026?

Generally Safe

Score 85/100

Viralism has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The security posture of Viralism v1.0.0 appears to be generally strong based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events, especially those lacking authentication or permission checks, significantly reduces the plugin's attack surface. Furthermore, the lack of critical or high-severity code signals like dangerous functions or taint flows with unsanitized paths is a positive indicator. The vulnerability history being clean with no recorded CVEs further reinforces this perception of a secure plugin.

However, there are areas that warrant attention. The SQL query analysis reveals that a significant percentage (64%) are not using prepared statements, which presents a risk of SQL injection vulnerabilities, especially if any of these queries handle user-supplied input directly or indirectly. Additionally, the fact that 100% of the single output identified is not properly escaped is a serious concern for cross-site scripting (XSS) vulnerabilities. While the plugin does perform one capability check, the absence of any nonce checks on its entry points is a notable weakness, particularly if any sensitive actions are performed. The bundling of DataTables, while common, could also introduce risks if it's an outdated version with known vulnerabilities.

In conclusion, Viralism v1.0.0 demonstrates good practices in minimizing its attack surface and has a clean vulnerability history. However, the potential for SQL injection due to un-prepared statements, XSS due to unescaped output, and the lack of nonce checks represent significant security risks that need to be addressed. The bundling of DataTables also warrants investigation for potential outdated versions.

Key Concerns

  • SQL queries not using prepared statements
  • Output not properly escaped
  • Missing nonce checks
  • Bundled library (DataTables)
Vulnerabilities
None known

Viralism Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Viralism Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Viralism Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
4 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

36% prepared11 total queries

Output Escaping

0% escaped1 total outputs
Attack Surface

Viralism Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menucode/functions.php:4
actionadmin_print_stylescode/functions.php:16
actionadmin_headcode/functions.php:42
Maintenance & Trust

Viralism Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJun 6, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Viralism Developer Profile

chatthasumit

3 plugins · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Viralism

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/viralism/css/bootstrap-3.3.7.min.css/wp-content/plugins/viralism/css/sweetalert.css/wp-content/plugins/viralism/css/templatemo-style.css/wp-content/plugins/viralism/css/custom-style.css/wp-content/plugins/viralism/js/bootstrap-3.3.7.min.js/wp-content/plugins/viralism/js/jquery.dataTables.min.js/wp-content/plugins/viralism/js/jquery.fancybox.min.js

HTML / DOM Fingerprints

CSS Classes
templatemo-content-widgettemplatemo-line-headertemplatemo-charttemplatemo-content-widget-margintemplatemo-header-margin
Data Attributes
data-toggledata-target
FAQ

Frequently Asked Questions about Viralism