Widget Actualites Relation Client Security & Risk Analysis

wordpress.org/plugins/widget-actualites-relation-client

Afficher sous la forme d'un widget l'actualité des principaux médias professionnels dans le domaine de la relation client

10 active installs v2.0 PHP + WP 2.0+ Updated Jan 9, 2016
feedfreenewssidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Widget Actualites Relation Client Safe to Use in 2026?

Generally Safe

Score 85/100

Widget Actualites Relation Client has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin "widget-actualites-relation-client" v2.0 exhibits a mixed security posture. On one hand, the plugin demonstrates good practices by avoiding dangerous functions, performing all SQL queries with prepared statements, and having no recorded vulnerabilities. The attack surface is also minimal, with no AJAX handlers, REST API routes, shortcodes, or cron events identified. This suggests a focus on a limited and controlled functionality.

However, significant concerns arise from the output escaping and taint analysis. 0% of outputs are properly escaped, which is a critical weakness that could lead to Cross-Site Scripting (XSS) vulnerabilities. This is further exacerbated by the taint analysis revealing 2 flows with unsanitized paths, although they are not categorized as critical or high severity in this specific analysis. The absence of nonce and capability checks on any entry points, while the attack surface is zero, still represents a missed opportunity for robust security, especially if functionality were to be expanded in the future.

Overall, while the plugin benefits from a clean vulnerability history and adherence to secure SQL practices, the severe lack of output escaping and the presence of unsanitized paths are substantial risks. These issues, if exploited, could allow for malicious code injection and unauthorized data manipulation. The plugin's current security is precarious due to these critical oversights, despite the absence of known exploits.

Key Concerns

  • No output escaping
  • Unsanitized paths in taint flows
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Widget Actualites Relation Client Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Widget Actualites Relation Client Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Widget Actualites Relation Client Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
35
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped35 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
widget_sgrss_troubleshooter (widget-actu-relation-client.php:543)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Widget Actualites Relation Client Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionsidebar_admin_setupwidget-actu-relation-client.php:533
actionsidebar_admin_pagewidget-actu-relation-client.php:534
actionwidgets_initwidget-actu-relation-client.php:566
actiontemplate_redirectwidget-actu-relation-client.php:567
Maintenance & Trust

Widget Actualites Relation Client Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJan 9, 2016
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Widget Actualites Relation Client Developer Profile

contacter

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Widget Actualites Relation Client

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widget-actualites-relation-client/widget-actualites-relation-client.php/wp-content/plugins/widget-actualites-relation-client/sgrss-js.js/wp-content/plugins/widget-actualites-relation-client/widget-actualites-relation-client.css
Script Paths
/wp-content/plugins/widget-actualites-relation-client/sgrss-js.js
Version Parameters
widget-actualites-relation-client/widget-actualites-relation-client.css?ver=widget-actualites-relation-client/sgrss-js.js?ver=

HTML / DOM Fingerprints

CSS Classes
sgrsswidget
Data Attributes
data-sgrss
JS Globals
sgrss_params
FAQ

Frequently Asked Questions about Widget Actualites Relation Client