
WP Calories Security & Risk Analysis
wordpress.org/plugins/wp-caloriesWP Calories shows a beautiful food photo whith calories ( kcal ) description on Your sidebar.
Is WP Calories Safe to Use in 2026?
Generally Safe
Score 85/100WP Calories has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-calories v1.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities and CVEs, coupled with the lack of dangerous functions and file operations, is highly positive. Notably, all SQL queries are secured using prepared statements, which significantly mitigates SQL injection risks. The attack surface is also remarkably small, with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without proper authentication or permission checks.
However, a significant concern arises from the output escaping. With 0% of outputs properly escaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any data processed or displayed by the plugin that originates from user input or external sources could be injected with malicious scripts, compromising user sessions or the website itself. The complete absence of nonce checks and capability checks also means that any existing entry points, however few, are not adequately protected against unauthorized actions.
Given the clean vulnerability history and the secure handling of SQL, the main weaknesses lie in the output escaping and the lack of nonce/capability checks. While the attack surface is minimal, the unescaped output presents a clear and present danger. Future versions should prioritize robust output sanitization and the implementation of proper authorization checks on all relevant entry points to achieve a more comprehensive security profile.
Key Concerns
- Output escaping is 0% proper
- Nonce checks are 0
- Capability checks are 0
WP Calories Security Vulnerabilities
WP Calories Release Timeline
WP Calories Code Analysis
Output Escaping
WP Calories Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP Calories Maintenance & Trust
Maintenance Signals
Community Trust
WP Calories Alternatives
Blipfoto importer
blipfoto-importer
Import journal entries and photos from a Blipfoto daily photo journal into your WordPress website.
LM Easy Slider
lm-easy-slider
LM Easy Slider is a plugin designed to make easy to insert sliders into a post, page or widget.
Smash Balloon Social Photo Feed – Easy Social Feeds Plugin
instagram-feed
Formerly "Instagram Feed". Display clean, customizable, and responsive Instagram feeds from multiple accounts. Supports Instagram oEmbeds.
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery
nextgen-gallery
The most popular gallery plugin that lets you create galleries and albums in seconds.
Firelight Lightbox
easy-fancybox
Formerly Easy Fancybox. The most popular WordPress lightbox plugin. Simple, fast, and responsive. Opens images, videos, PDFs, and custom popups.
WP Calories Developer Profile
6 plugins · 60 total installs
How We Detect WP Calories
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-calories/images/bg.pngHTML / DOM Fingerprints
wp_calories_imgwp_caloriesid="wp_calories_image_in"id="img_wp_calories"id="desc_wp_calories"id="url_wp_calories"id="wp_calories_kcal_txt"id="wp_calories_kcal_txt_s"<ul class="wp_calories"><img class="wp_calories_img"id="wp_calories_kcal_txt"><span id="wp_calories_kcal_txt_s">kcal</span>