
QR code MeCard/vCard generator Security & Risk Analysis
wordpress.org/plugins/wp-qrcode-me-v-cardShare your contact information such as emails, phone number and much more through QR code with WordPress using shortcode, widget or by direct link.
Is QR code MeCard/vCard generator Safe to Use in 2026?
Generally Safe
Score 100/100QR code MeCard/vCard generator has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-qrcode-me-vcard plugin version 1.7.1 presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and performing some capability checks, significant concerns remain. The presence of an unprotected AJAX handler significantly expands the attack surface, as any unauthenticated user could potentially interact with this endpoint. The lack of proper output escaping on a substantial portion (84%) of outputs is also a serious concern, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The plugin's vulnerability history shows one past medium-severity vulnerability, specifically related to missing authorization, which aligns with the current finding of an unprotected AJAX handler. This pattern suggests a recurring weakness in ensuring proper access control for plugin functionalities.
Overall, the plugin has some security strengths, particularly in its database interactions. However, the identified unprotected entry point and the high percentage of unescaped output introduce considerable risk. The historical pattern of missing authorization further reinforces the need for diligent review and remediation of access control mechanisms. The absence of critical or high severity taint flows is a positive sign, but the existing issues are sufficient to warrant caution and prompt remediation.
Key Concerns
- Unprotected AJAX handler found
- High percentage of unescaped output
- Past medium vulnerability (Missing Authorization)
QR code MeCard/vCard generator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
QR code MeCard/vCard generator <= 1.6.0 - Missing Authorization via wqm_make_url_permanent
QR code MeCard/vCard generator Code Analysis
SQL Query Safety
Output Escaping
QR code MeCard/vCard generator Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
QR code MeCard/vCard generator Maintenance & Trust
Maintenance Signals
Community Trust
QR code MeCard/vCard generator Alternatives
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
QR Code
qr-code
It lets appear the QR-code of the given site in the slidebar
Super Cool QRCode
super-cool-qrcode
Easily insert QR codes in your blog, with Widget or Shortcode.
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
QR code MeCard/vCard generator Developer Profile
4 plugins · 5K total installs
How We Detect QR code MeCard/vCard generator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-qrcode-me-v-card/static/css/styles.css/wp-content/plugins/wp-qrcode-me-v-card/static/js/wp-color-picker-alpha.min.jswp-qrcode-me-v-card/static/css/styles.css?ver=wp-qrcode-me-v-card/static/js/wp-color-picker-alpha.min.js?ver=HTML / DOM Fingerprints
wqm-color-pickerwpColorPicker