Embed charts graphs tables and forms with Vixo Security & Risk Analysis

wordpress.org/plugins/vixo-embeddable-tables-charts-and-spreadsheets

Lets you embed graphs and graphs, tables, spreadsheets, forms and quotation engines from the Vixo online spreadsheet.

20 active installs v1.5 PHP + WP 3.0.1+ Updated Mar 26, 2013
chartsformsgraphsspreadsheetstables
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Embed charts graphs tables and forms with Vixo Safe to Use in 2026?

Generally Safe

Score 85/100

Embed charts graphs tables and forms with Vixo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The vixo-embeddable-tables-charts-and-spreadsheets plugin v1.5 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and a commitment to prepared statements for all SQL queries are excellent indicators of secure coding practices. Furthermore, the complete output escaping and the lack of any recorded vulnerabilities in its history suggest a well-maintained and secure plugin. The analysis also indicates no critical or high-severity taint flows, further bolstering its security standing.

While the plugin demonstrates impressive security hygiene, the static analysis reveals a complete absence of nonce checks and capability checks across all entry points, including its single shortcode. This is a notable concern, as it means any user, regardless of their role or permissions, could potentially trigger the functionality of the shortcode. Although there are no AJAX handlers or REST API routes to exploit in this specific version, the lack of authorization checks on the shortcode itself presents a potential attack vector if the shortcode's functionality could be leveraged maliciously without proper user context. In conclusion, the plugin is technically robust in its code implementation, but the lack of authorization checks on its sole entry point is a critical weakness that needs to be addressed to ensure true security.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Embed charts graphs tables and forms with Vixo Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Embed charts graphs tables and forms with Vixo Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Embed charts graphs tables and forms with Vixo Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[vixo] vixo-shortcode.php:7
Maintenance & Trust

Embed charts graphs tables and forms with Vixo Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedMar 26, 2013
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

Embed charts graphs tables and forms with Vixo Developer Profile

Gordon Guthrie

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Embed charts graphs tables and forms with Vixo

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vixo-embeddable-tables-charts-and-spreadsheets/vixo.wordpress.css/wp-content/plugins/vixo-embeddable-tables-charts-and-spreadsheets/vixo.wordpress.js/wp-content/plugins/vixo-embeddable-tables-charts-and-spreadsheets/jquery.ba-postmessage.js
Script Paths
/wp-content/plugins/vixo-embeddable-tables-charts-and-spreadsheets/vixo.wordpress.js/wp-content/plugins/vixo-embeddable-tables-charts-and-spreadsheets/jquery.ba-postmessage.js
Version Parameters
vixo.wordpress.css?ver=vixo.wordpress.js?ver=jquery.ba-postmessage.js?ver=

HTML / DOM Fingerprints

CSS Classes
hn_wordpresshn_dont_resize
HTML Comments
<!--No Vixo Url -->
Data Attributes
id=''class='hn_wordpressstyle=''src=''data-url=''
JS Globals
window.vixo_resize
Shortcode Output
<iframe id='' class='hn_wordpress' style='' src='
FAQ

Frequently Asked Questions about Embed charts graphs tables and forms with Vixo