WP Car Security & Risk Analysis

wordpress.org/plugins/wp-car

WP Car shows a car photo whith horsepower( HP ) description on Your sidebar.

10 active installs v1.1 PHP + WP 2.3+ Updated Sep 29, 2010
brake-horse-powercarcars-performanceperformanceperformance-car
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Car Safe to Use in 2026?

Generally Safe

Score 85/100

WP Car has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "wp-car" plugin v1.1 demonstrates a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs and the lack of dangerous functions or SQL queries without prepared statements are strong indicators of good development practices regarding known vulnerabilities and common attack vectors. The plugin also shows no external HTTP requests or file operations, which limits potential attack surfaces.

However, the static analysis reveals a critical concern: 100% of its outputs are not properly escaped. This is a significant weakness as it opens the door to Cross-Site Scripting (XSS) vulnerabilities. Attackers could potentially inject malicious scripts into the WordPress frontend through this plugin's outputs, compromising user sessions or performing actions on their behalf. The lack of nonces and capability checks, while not directly indicative of a vulnerability in isolation given the zero entry points, means that if any entry points were to be introduced in the future, they would lack essential security measures.

In conclusion, while the plugin is free from known vulnerabilities and common exploitable code patterns, the pervasive lack of output escaping is a serious risk that needs immediate attention. This oversight could lead to severe XSS attacks. The plugin's strengths lie in its minimal attack surface and adherence to secure SQL practices, but its primary weakness in output sanitization overshadows these benefits and necessitates remediation.

Key Concerns

  • Outputs are not properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP Car Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Car Release Timeline

v1.1Current
v1.0
Code Analysis
Analyzed Apr 16, 2026

WP Car Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped4 total outputs
Attack Surface

WP Car Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionplugins_loadedwp-car.php:196
Maintenance & Trust

WP Car Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedSep 29, 2010
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WP Car Developer Profile

jakubas

6 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Car

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-car/images/bugatti_veyron.jpg/wp-content/plugins/wp-car/images/ultima_gtr.jpg/wp-content/plugins/wp-car/images/ssc-ultimate-aero.jpg/wp-content/plugins/wp-car/images/ascari_a10.jpg/wp-content/plugins/wp-car/images/ariel-atom.jpg/wp-content/plugins/wp-car/images/porsche-911-turbo-s.jpg/wp-content/plugins/wp-car/images/ferrari-458-italia.jpg/wp-content/plugins/wp-car/images/rossion-q1.jpg+13 more

HTML / DOM Fingerprints

CSS Classes
wp_carwp_car_img
Shortcode Output
<ul class="wp_car"><a rel="nofallow" title=<img class="wp_car_img" src=brake horsepower
FAQ

Frequently Asked Questions about WP Car