
WP Google Charts Security & Risk Analysis
wordpress.org/plugins/wp-google-chartsEasily integrate google charts, diagrams and tables based on your Google Spreadsheets.
Is WP Google Charts Safe to Use in 2026?
Generally Safe
Score 85/100WP Google Charts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-google-charts" v1.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by having a limited attack surface with only one shortcode as an entry point and no AJAX handlers or REST API routes. Crucially, all detected SQL queries utilize prepared statements, and there are no known critical or high severity vulnerabilities in its history. This suggests a diligent development approach regarding common web application vulnerabilities.
However, a significant concern arises from the static analysis, specifically the lack of output escaping. With 29 total outputs and 0% properly escaped, there is a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed by the plugin without proper sanitization could be exploited to inject malicious scripts. Furthermore, the absence of nonce checks and capability checks on its single entry point (the shortcode) means that it doesn't adequately verify user permissions or protect against Cross-Site Request Forgery (CSRF) attacks, particularly if the shortcode displays dynamic data.
The plugin's clean vulnerability history is a positive indicator of past security awareness. However, the current static analysis reveals a critical oversight in output sanitization and authorization checks that could overshadow this good history. The lack of proper escaping is a direct pathway to XSS, and the missing authorization checks present CSRF risks, especially when dealing with potentially sensitive chart data or configurations.
Key Concerns
- 0% output escaping on 29 outputs
- Missing nonce checks on entry points
- Missing capability checks on entry points
WP Google Charts Security Vulnerabilities
WP Google Charts Code Analysis
Output Escaping
WP Google Charts Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
WP Google Charts Maintenance & Trust
Maintenance Signals
Community Trust
WP Google Charts Alternatives
Charts Ninja: Create Beautiful Graphs & Charts and Easily Add Them to Your Website
charts-ninja-graphs-and-charts
Create Beautiful Graphs & Charts with our Charts maker and Easily Add Them to Your Website. All chart types supported! Powered by Common Ninja.
MarketPress Statistics
marketpress-statistics
Display MarketPress statistics using google charts.
Chartivio
chartivio
Professional, interactive data visualization for WordPress. Create stunning charts with a live-preview editor, CSV support, and manual data entry.
Visualizer: Tables and Charts Manager for WordPress
visualizer
A simple yet powerful WordPress chart plugin to effortlessly create and embed responsive charts & tables into your site, supporting multiple data …
Graphina – Charts and Graphs For Elementor
graphina-elementor-charts-and-graphs
Most Powerful Data visualization plugin for WordPress Elementor. The easiest way to build gorgeous Charts & Graphs on your Elementor website.
WP Google Charts Developer Profile
3 plugins · 170 total installs
How We Detect WP Google Charts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-google-charts/wp-google-charts.phpHTML / DOM Fingerprints
google.visualization.Querygoogle.visualization.DataViewgoogle.visualization.ColumnChartgoogle.visualization.AreaChartgoogle.visualization.BarChart<div id="agcnew google.visualization.Query(handleQueryResponse