
Widget Github Profile Security & Risk Analysis
wordpress.org/plugins/widget-github-profileShows your github profile in detail.
Is Widget Github Profile Safe to Use in 2026?
Generally Safe
Score 85/100Widget Github Profile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "widget-github-profile" v1.0.0 plugin exhibits a strong security posture in several key areas, notably the absence of known vulnerabilities and a lack of identified critical or high-severity taint flows. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries, indicating a reduced risk of SQL injection. However, there are significant concerns regarding output escaping, with only 10% of observed outputs being properly escaped. This widespread lack of escaping is a critical vulnerability that could lead to Cross-Site Scripting (XSS) attacks. Furthermore, the plugin performs an external HTTP request without any clear indication of authentication or authorization checks, which could potentially expose sensitive data or be exploited for server-side request forgery (SSRF) if not handled securely. The absence of AJAX handlers, REST API routes, shortcodes, and cron events means the direct attack surface is currently minimal, but this is overshadowed by the output escaping and external request vulnerabilities. The lack of recorded vulnerability history is a positive sign but doesn't negate the inherent risks identified in the code analysis.
Key Concerns
- Low output escaping (10%)
- External HTTP request without auth/caps
- No nonce checks on AJAX
- No capability checks
Widget Github Profile Security Vulnerabilities
Widget Github Profile Code Analysis
Output Escaping
Widget Github Profile Attack Surface
WordPress Hooks 2
Maintenance & Trust
Widget Github Profile Maintenance & Trust
Maintenance Signals
Community Trust
Widget Github Profile Alternatives
Card Elements for Elementor
card-elements-for-elementor
Showcase useful elements with card style for elementor page builder.
Amazing WPBakery Page Builder Addons
amazing-wpbakery-page-builder-addons
Bundled with super useful WPBakery Page Builder elements with bunch of options to achieve any design with all the power of WPBakery Page Builder for f …
Profile Card Block
block-profile-card
display profile in card formate in your wordpress-site with custom block.
Creative Tim's Rotating CSS Cards
creative-tim-rotating-css-cards
This plugin will allow WordPress developers to use Creative Tim's Rotating CSS Cards through a programmable shortcode.
Premium Profile Card Addon for Elementor
premium-profile-card-addon-for-elementor
Create beautiful, fully customizable user profile cards with advanced style controls directly inside Elementor.
Widget Github Profile Developer Profile
1 plugin · 10 total installs
How We Detect Widget Github Profile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widget-github-profile/style.csswidget-github-profile/style.css?ver=1.0.0HTML / DOM Fingerprints
github-profile-cardg-avatarg-namesg-nameg-nicknameg-followg-profile-statsg-stat-title+3 moredata-github-username