
Plotly Security & Risk Analysis
wordpress.org/plugins/wp-plotlyEmbed Plotly graphs in wordpress admin.
Is Plotly Safe to Use in 2026?
Mostly Safe
Score 84/100Plotly is generally safe to use though it hasn't been updated recently. 2 past CVEs were resolved. Keep it updated.
The wp-plotly plugin v1.0.2 exhibits a generally strong security posture based on the static analysis. The absence of direct entry points such as AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate a commendable commitment to security best practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and all outputs being properly escaped. The absence of file operations and external HTTP requests further reduces potential vectors for compromise. However, a significant concern arises from the plugin's vulnerability history. The presence of two known medium-severity CVEs, both related to Cross-Site Scripting (XSS), and the fact that the last vulnerability was in 2015 suggests a potential for unaddressed security flaws. While no vulnerabilities are currently unpatched, the historical pattern indicates a past susceptibility to XSS, which could be a latent risk if not thoroughly remediated in newer, unanalyzed versions.
In conclusion, while the static analysis of v1.0.2 demonstrates good coding practices and a minimal attack surface, the historical vulnerability data presents a notable weakness. The plugin's past struggles with XSS, even if resolved in later versions, warrant cautious consideration. A comprehensive security assessment would require analyzing more recent versions to confirm the permanent resolution of these past issues and to identify any new potential vulnerabilities.
Key Concerns
- Past unpatched medium CVEs
- History of XSS vulnerabilities
Plotly Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Plotly <= 1.0.2 - Stored Cross-Site Scripting
Plotly < 1.0.3 - Stored Cross-Site Scripting
Plotly Code Analysis
Plotly Attack Surface
WordPress Hooks 2
Maintenance & Trust
Plotly Maintenance & Trust
Maintenance Signals
Community Trust
Plotly Alternatives
Seed Fonts
seed-fonts
Use web fonts (@font-face) by choosing from Google Fonts, Bundled Thai-English fonts, and your own web fonts.
Visualizer: Tables and Charts Manager for WordPress
visualizer
A simple yet powerful WordPress chart plugin to effortlessly create and embed responsive charts & tables into your site, supporting multiple data …
Graphina – Charts and Graphs For Elementor
graphina-elementor-charts-and-graphs
Most Powerful Data visualization plugin for WordPress Elementor. The easiest way to build gorgeous Charts & Graphs on your Elementor website.
Chartify – WordPress Chart Plugin
chart-builder
Chartify is a powerful WordPress Chart Builder Plugin that will help you to create WordPress Graphs & Charts easily and quickly.
M Chart
m-chart
Manage data sets and display them as charts in WordPress.
Plotly Developer Profile
1 plugin · 100 total installs
How We Detect Plotly
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://plot.ly/embed.jsHTML / DOM Fingerprints
data-plotly<div><a href='https://plot.ly/~