Word Look Security & Risk Analysis

wordpress.org/plugins/word-look

A lightweight WordPress plugin that lets users double-click on any word in your site's content to get its meaning using an external dictionary API.

0 active installs v1.0.0 PHP 8.0+ WP 5.0+ Updated Jun 18, 2025
dictionarydouble-clickfrontend-dictionarytooltipword-meaning
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Word Look Safe to Use in 2026?

Generally Safe

Score 100/100

Word Look has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "word-look" plugin v1.0.0 demonstrates a strong security posture based on the provided static analysis. There are no identified vulnerabilities in its attack surface, code signals, or taint analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, nonce checks, or capability checks is highly commendable and indicates adherence to secure coding practices. The plugin also has no known historical vulnerabilities, which further reinforces its current secure state.

However, the complete lack of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual for a typical WordPress plugin. While this contributes to its current low-risk profile by minimizing the attack surface, it might indicate that the plugin's functionality is very limited or entirely non-interactive. If the plugin is intended to provide user-facing features, the absence of these common integration points could be a functional limitation rather than a security strength. The plugin's strengths lie in its clean code and lack of known issues, but its minimal apparent functionality might warrant further investigation into its intended purpose.

Vulnerabilities
None known

Word Look Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Word Look Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Word Look Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_enqueue_scriptsword-look.php:26
actionwp_footerword-look.php:27
Maintenance & Trust

Word Look Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 18, 2025
PHP min version8.0
Downloads201

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Word Look Developer Profile

codedbyabir

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Word Look

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/word-look/assets/css/style.css/wp-content/plugins/word-look/assets/js/custom.js
Script Paths
/wp-content/plugins/word-look/assets/js/custom.js
Version Parameters
word-look/assets/css/style.css?ver=word-look/assets/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
wdlook-wordMeaningModalwdlook-word-modal-contentwdlook-close-wrapperwdlook-word-closewdlook-selectedWordwdlook-wordDefinition
FAQ

Frequently Asked Questions about Word Look