WP-Clippy Security & Risk Analysis

wordpress.org/plugins/wp-clippy

Adds a flash button that copies the value of an element or string to the clipboard when clicked.

10 active installs v1.0.0 PHP + WP 2.8+ Updated Jan 1, 2013
buttonclipboardcopyflashshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP-Clippy Safe to Use in 2026?

Generally Safe

Score 85/100

WP-Clippy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The wp-clippy v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for SQL queries, and proper output escaping are commendable practices. The plugin also correctly handles file operations and external HTTP requests, further bolstering its security.

The analysis shows a very small attack surface, with only one shortcode identified and no unprotected entry points. The lack of any reported vulnerabilities in its history is also a positive indicator, suggesting a history of secure development or limited exposure. The absence of taint flows with unsanitized paths or critical/high severity issues further reinforces this positive assessment.

However, the plugin has no recorded capability checks or nonce checks for its entry points. While the attack surface is currently minimal, this could represent a potential risk if the plugin's functionality were to expand or if new vulnerabilities were introduced in future updates without implementing these essential security measures. Overall, wp-clippy v1.0.0 appears to be a secure plugin, but the absence of explicit authorization checks presents a minor area for improvement.

Key Concerns

  • Missing capability checks on entry points
  • Missing nonce checks on entry points
Vulnerabilities
None known

WP-Clippy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WP-Clippy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

WP-Clippy Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[clippy] wp-clippy.php:78
Maintenance & Trust

WP-Clippy Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJan 1, 2013
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WP-Clippy Developer Profile

Luke Mlsna

11 plugins · 13K total installs

83
trust score
Avg Security Score
84/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP-Clippy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-clippy/wp-clippy.swf

HTML / DOM Fingerprints

CSS Classes
wp-clippy-embed
HTML Comments
Plugin: WP-Clippy Plugin URI: http://shinraholdings.com/plugins/wp-clippy WordPress plugin for copying input values or strings to the clipboard.
Data Attributes
id="wp-clippy-embed"id="wp-clippy"
Shortcode Output
<p id="wp-clippy-embed"<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="68" height="25" id="wp-clippy"<object type="application/x-shockwave-flash" data="
FAQ

Frequently Asked Questions about WP-Clippy