WordPlurk improve Security & Risk Analysis

wordpress.org/plugins/wordplurk-improve

WordPlurk improve is Base on 'WordPlurk', and add more settings and functions.

10 active installs v3.2 PHP + WP 3.0+ Updated Dec 20, 2012
plurk
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WordPlurk improve Safe to Use in 2026?

Generally Safe

Score 85/100

WordPlurk improve has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The wordplurk-improve v3.2 plugin exhibits a generally strong security posture in several key areas. Notably, there are no recorded vulnerabilities, including critical or high-severity ones, and no known CVEs associated with this version. The plugin also demonstrates good practices regarding database interactions, with all SQL queries utilizing prepared statements. Furthermore, the static analysis shows a zero attack surface for AJAX handlers, REST API routes, shortcodes, and cron events without proper authorization checks, indicating a deliberate effort to limit direct entry points for potential attackers.

However, a significant concern arises from the complete lack of output escaping. With 19 total outputs analyzed and 0% properly escaped, this presents a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Any data processed and displayed by the plugin could potentially be manipulated by attackers to inject malicious scripts, which could then be executed in the browser of other users. The absence of nonce checks and capability checks also suggests a potential weakness in securing actions that might modify data or perform sensitive operations, especially if there were any undiscovered entry points.

While the plugin's clean vulnerability history is a positive indicator, it should not be solely relied upon. The significant weakness in output escaping needs immediate attention. The absence of any recorded vulnerabilities could be due to a lack of thorough security audits or the plugin's limited usage. The plugin has strengths in its controlled entry points and secure SQL practices, but the unescaped output represents a critical flaw that needs to be addressed to mitigate significant security risks.

Key Concerns

  • All outputs are unescaped
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

WordPlurk improve Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WordPlurk improve Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
19
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped19 total outputs
Attack Surface

WordPlurk improve Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actiontransition_post_statuswordplurk-improve.php:135
actiondbx_post_advancedwordplurk-improve.php:144
actionadmin_menuwordplurk-improve.php:181
actionadmin_initwordplurk-improve.php:182
actionadmin_noticeswordplurk-improve.php:184
filterthe_contentwordplurk-improve.php:185
actioninitwordplurk-improve.php:193
actionplugins_loadedwordplurk-improve.php:247
Maintenance & Trust

WordPlurk improve Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedDec 20, 2012
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WordPlurk improve Developer Profile

renn999

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WordPlurk improve

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
wordplurk-improve/style.css?ver=wordplurk-improve/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wordplurk_fieldsetiddbx-b-ox-wrapperdbx-boxdbx-h-andle-wrapperdbx-handledbx-c-ontent-wrapperdbx-content
HTML Comments
<!-- Prints the edit form for pre-WordPress 2.5 post/page -->
Data Attributes
id="wordplurk_sectionid"name="wordplurk_noncename"id="wordplurk_noncename"name="wordplurk_plurkornot"id="wordplurk_plurkornot"id="wordplurk_fieldsetid"
FAQ

Frequently Asked Questions about WordPlurk improve