WP Design Portfolio Security & Risk Analysis

wordpress.org/plugins/wp-design-portfolio

Wordpress Design Portfolio is a portfolio plugin which design your portfolio as well as your image gallery. This is a lite plugin which load faster.

10 active installs v1.0.2 PHP 7.0+ WP 4.8+ Updated Sep 22, 2020
best-gallery-plugincreate-portfoliodesign-portfoliowordpress-gallery-portfoliowordpress-portfolio-plugin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Design Portfolio Safe to Use in 2026?

Generally Safe

Score 85/100

WP Design Portfolio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "wp-design-portfolio" plugin version 1.0.2 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and SQL queries not using prepared statements are positive indicators. Furthermore, the plugin's attack surface is minimal, consisting solely of one shortcode, with no direct unprotected entry points identified.

However, there are areas for improvement that introduce potential risks. The most significant concern is the low percentage of properly escaped output (40%), meaning there's a high chance of cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed. Additionally, the complete lack of nonce checks and capability checks, even on the single shortcode, suggests a potential for authorization and CSRF vulnerabilities. The vulnerability history being clean is a positive sign, but it does not negate the risks identified in the code analysis.

In conclusion, while the plugin avoids common pitfalls like raw SQL or dangerous functions, the insufficient output escaping and lack of authorization checks represent notable security weaknesses. Addressing these concerns would significantly improve the plugin's overall security. The current state indicates a developer who is mindful of some security best practices but has overlooked crucial aspects of input sanitization and authorization.

Key Concerns

  • Insufficient output escaping (60% unescaped)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

WP Design Portfolio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Design Portfolio Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

WP Design Portfolio Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

40% escaped5 total outputs
Attack Surface

WP Design Portfolio Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wp_portfolio] inc/wp-portfolio-shortcode.php:2
WordPress Hooks 3
actionwp_enqueue_scriptswordpress-portfolio.php:69
actionwp_footerwordpress-portfolio.php:73
actioninitwordpress-portfolio.php:76
Maintenance & Trust

WP Design Portfolio Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 22, 2020
PHP min version7.0
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WP Design Portfolio Developer Profile

Jahirul Islam Mamun

2 plugins · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Design Portfolio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-design-portfolio/css/custom.min.css/wp-content/plugins/wp-design-portfolio/js/plugin.js
Script Paths
/wp-content/plugins/wp-design-portfolio/js/plugin.js
Version Parameters
wp-design-portfolio/css/custom.min.css?ver=wp-design-portfolio/js/plugin.js?ver=

HTML / DOM Fingerprints

CSS Classes
isotope-itemsitemitem-witem-hisotope-filtersisotope-masonry-items
Data Attributes
data-filter
JS Globals
XTL_P_URLXTL_P_DIR
FAQ

Frequently Asked Questions about WP Design Portfolio