
WODTogether Whiteboards Security & Risk Analysis
wordpress.org/plugins/wodtogether-whiteboardsAllows embedding of WODTogether whiteboards into your blog posts automatically.
Is WODTogether Whiteboards Safe to Use in 2026?
Generally Safe
Score 85/100WODTogether Whiteboards has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wodtogether-whiteboards" plugin version 3.3.1 presents a mixed security profile. On the positive side, the static analysis reveals no identified entry points like AJAX handlers, REST API routes, or shortcodes, which significantly limits the potential attack surface. Furthermore, there are no dangerous functions, file operations, or external HTTP requests detected, and all SQL queries utilize prepared statements. The vulnerability history is also clean, with no known CVEs recorded, indicating a generally well-maintained past.
However, a significant concern arises from the complete lack of output escaping. With 7 total outputs identified and 0% properly escaped, this creates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any dynamic data displayed by the plugin is susceptible to manipulation, potentially allowing attackers to inject malicious scripts into the user's browser. Additionally, the absence of nonce and capability checks, while not directly exploitable without an entry point, means that if an entry point were to be introduced in a future update or through another vulnerability, the plugin would be immediately vulnerable to unauthorized actions and privilege escalation.
In conclusion, while the plugin has a strong foundation with a minimal attack surface and secure database practices, the critical lack of output escaping is a severe weakness that demands immediate attention. The absence of nonce and capability checks, though less immediately critical in this specific version, represents a latent risk that should be addressed to improve the plugin's overall security posture.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
WODTogether Whiteboards Security Vulnerabilities
WODTogether Whiteboards Code Analysis
Output Escaping
WODTogether Whiteboards Attack Surface
WordPress Hooks 4
Maintenance & Trust
WODTogether Whiteboards Maintenance & Trust
Maintenance Signals
Community Trust
WODTogether Whiteboards Alternatives
Intagrate Lite
instagrate-to-wordpress
Automatically post your Instagram images to your WordPress site. Create new WordPress posts from your Instagram images, save the Instagram image to th …
Feeds for Twitter – Embed Social Media Posts with Live Updates
easy-twitter-feeds
Embed Twitter Timeline/Feed, Post, Video, Hashtag, Follow Button, Tweet Button easily. This plugin is lightweight but super powerful.
Embed Iframe
embed-iframe
Allows the insertion of code to display an external webpage within an iframe.
Magyar Video Embed
magyar-video-embed
This plugin helps different hungarian online video service provider videos to be embeded just like youtube links. So, this is not intresting to you un …
PageView
pageview
Insert an iframe and display an external website directly in a post using just a shortcode.
WODTogether Whiteboards Developer Profile
1 plugin · 10 total installs
How We Detect WODTogether Whiteboards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wodtogether-whiteboards/wodtogether-whiteboards.css/wp-content/plugins/wodtogether-whiteboards/wodtogether-whiteboards.jswodtogether-whiteboards/wodtogether-whiteboards.css?ver=wodtogether-whiteboards/wodtogether-whiteboards.js?ver=HTML / DOM Fingerprints
wodtogether-whiteboardsid="wodtogether_gym_id"name="wodtogether_options[gym_id]"id="wodtogether_program_id"name="wodtogether_options[program_id]"id="wodtogether_date_offset"name="wodtogether_options[date_offset]"+6 more