Web Rank Get Security & Risk Analysis

wordpress.org/plugins/web-rank-get

This plugin will collect Google Page Rank and Alexa Rank and display it in the footer of your blog.

10 active installs v1.0 PHP + WP 3.0+ Updated Sep 23, 2011
alexaalexa-rankgoogle-page-rankpage-rankseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Web Rank Get Safe to Use in 2026?

Generally Safe

Score 85/100

Web Rank Get has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The web-rank-get plugin v1.0 exhibits a generally positive security posture with no known vulnerabilities in its history and a lack of critical code signals like dangerous functions or external HTTP requests. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating a capability check. This suggests a developer who is aware of basic security principles.

However, a significant concern arises from the complete lack of output escaping for the five identified output points. This is a critical weakness as it opens the door to Cross-Site Scripting (XSS) vulnerabilities. Any data rendered to the user interface without proper sanitization could be manipulated by an attacker to inject malicious scripts, leading to session hijacking, defacement, or other harmful actions. Furthermore, the absence of nonce checks and the low number of capability checks, while not directly indicative of a vulnerability in this specific version, suggests a potential for future security oversights if the plugin grows in complexity or if new entry points are introduced without adequate protection.

In conclusion, while the plugin's current history and core coding practices are commendable, the unescaped output represents a clear and present danger. Addressing this output escaping issue should be the immediate priority to mitigate the risk of XSS attacks. The plugin's attack surface is currently minimal, but ongoing vigilance and adherence to secure coding practices will be crucial as it evolves.

Key Concerns

  • 0% output escaping found
  • 0 nonce checks found
Vulnerabilities
None known

Web Rank Get Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Web Rank Get Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

Web Rank Get Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initweb-rank-get.php:35
actionadmin_menuweb-rank-get.php:36
filterplugin_action_linksweb-rank-get.php:37
actionadmin_print_stylesweb-rank-get.php:38
actionadmin_print_scriptsweb-rank-get.php:39
actionwp_footerweb-rank-get.php:260
Maintenance & Trust

Web Rank Get Maintenance & Trust

Maintenance Signals

WordPress version tested3.2.1
Last updatedSep 23, 2011
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Web Rank Get Developer Profile

hostinginfo360

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Web Rank Get

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/web-rank-get/web-rank-get.css

HTML / DOM Fingerprints

CSS Classes
webrankget_settings
FAQ

Frequently Asked Questions about Web Rank Get