
WP eCards – Branded Digital Greeting Cards Security & Risk Analysis
wordpress.org/plugins/wp-ecards-invitesAdd interactive digital greeting cards to your WordPress site — fully branded, customizable, and shareable by visitors through email or social media.
Is WP eCards – Branded Digital Greeting Cards Safe to Use in 2026?
Generally Safe
Score 99/100WP eCards – Branded Digital Greeting Cards has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wp-ecards-invites plugin, version 1.4.12, exhibits a generally positive security posture based on the static analysis. The absence of direct AJAX handlers and REST API routes without authentication, coupled with 100% prepared SQL statements and presence of nonce and capability checks, indicates good development practices in these areas. Furthermore, the lack of critical or high severity taint flows and dangerous function usage suggests a low risk of code injection or execution vulnerabilities originating from the analyzed code paths.
However, a significant concern arises from the output escaping, where 27% of outputs are not properly escaped. This leaves the plugin susceptible to Cross-Site Scripting (XSS) vulnerabilities, especially given that the plugin has a history of XSS vulnerabilities. The presence of one known CVE, although currently unpatched, and specifically a medium severity XSS vulnerability in the past, reinforces this concern. While the current static analysis doesn't reveal an active XSS flaw, the historical pattern and the unescaped output percentage warrant caution.
In conclusion, the plugin has strengths in its secure handling of database queries and user authentication for entry points. The primary weakness lies in insufficient output sanitization, which, combined with past XSS vulnerabilities, presents a notable risk. Addressing the unescaped output is crucial for improving the plugin's overall security and preventing potential XSS attacks.
Key Concerns
- High percentage of unescaped output
- Past medium severity XSS vulnerability
WP eCards – Branded Digital Greeting Cards Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP eCards <= 1.3.904 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP eCards – Branded Digital Greeting Cards Release Timeline
WP eCards – Branded Digital Greeting Cards Code Analysis
Output Escaping
Data Flow Analysis
WP eCards – Branded Digital Greeting Cards Attack Surface
Shortcodes 2
WordPress Hooks 23
Maintenance & Trust
WP eCards – Branded Digital Greeting Cards Maintenance & Trust
Maintenance Signals
Community Trust
WP eCards – Branded Digital Greeting Cards Alternatives
Invitations for Slack
invitations-for-slack
Build a Slack community by allowing your visitors (or registered users) to invite themselves to your Slack team.
WP Social Invites
wp-social-invites
WP Social Invites allows your visitors to invite their social friends on your website.
Invite Anyone
invite-anyone
Makes BuddyPress's invitation features more powerful.
Voice Search
voice-search
Allows visitors to search the site using their voice.
eCards Lite
ecards-lite
eCards is a WordPress plugin used to send electronic cards (eCards) to friends.
WP eCards – Branded Digital Greeting Cards Developer Profile
1 plugin · 400 total installs
How We Detect WP eCards – Branded Digital Greeting Cards
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-ecards-invites/admin/css/wp-ecards-admin.csshttps://wp.ecardwidget.com/assets/app/vendor/resizerLatest/iframeResizer.min.jswp-ecards-invites/admin/css/wp-ecards-admin.css?ver=HTML / DOM Fingerprints
ecardwidget-maindata-ecardwidget-urlecardwidget_vars[ecardwidget]