
WP Facts Security & Risk Analysis
wordpress.org/plugins/wp-factsWP Facts shows a simple facts-photo whith short description on Your sidebar.
Is WP Facts Safe to Use in 2026?
Generally Safe
Score 85/100WP Facts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-facts" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals show no dangerous functions, no direct file operations, no external HTTP requests, and all SQL queries utilize prepared statements. The lack of recorded vulnerabilities in its history is also a positive indicator.
However, a significant concern arises from the complete lack of output escaping. With 4 total outputs analyzed and 0% properly escaped, this represents a critical weakness. Any data displayed to users, whether user-supplied or not, is vulnerable to cross-site scripting (XSS) attacks. Additionally, the absence of nonce checks and capability checks, while potentially justified by the limited attack surface, could become a problem if new entry points are introduced in future versions without proper security considerations.
In conclusion, while the plugin has a clean history and a minimal attack surface, the unescaped output is a serious vulnerability that needs immediate attention. The lack of nonce and capability checks also suggests a potentially underdeveloped security awareness, which could lead to future issues if the plugin's functionality expands.
Key Concerns
- Output escaping is missing
- No nonce checks
- No capability checks
WP Facts Security Vulnerabilities
WP Facts Code Analysis
Output Escaping
WP Facts Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP Facts Maintenance & Trust
Maintenance Signals
Community Trust
WP Facts Alternatives
Fun Facts
fun-facts
Adds a sidebar widget that display interesting, useless, weird and wonderful random fun facts.
Server IP & Memory Usage Display
server-ip-memory-usage
Show the memory limit, current memory usage and IP address in the admin footer.
Top Bar
top-bar
Simply the easiest way to add a topbar to your website. Create a notification bar in no-time and show a message and a button to your visitors.
VOD Infomaniak
vod-infomaniak
Easily embed and manage videos from Infomaniak VOD in your posts, comments and RSS feeds. You need an Infomaniak VOD account to use this plugin.
Counter Number Showcase, Fun Facts – WordPress Animated Counter Plugin
counter-number-showcase
Counter Number WordPress Plugin brings you all the powerful Stats Counter features to your wordpress website
WP Facts Developer Profile
4 plugins · 40 total installs
How We Detect WP Facts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-facts/images/bg.pngHTML / DOM Fingerprints
wp_factswp_facts_imgid="wp-facts"id="wp_facts_image_in"id="img_wp_facts"id="url_wp_facts"id="desc_wp_facts"<ul class="wp_facts"><div id="img_wp_facts"><img class="wp_facts_img"<div id='url_wp_facts' style='font-size: 8px; line-height: 10px; height: 10px;'>