
WP Showcase for GitHub Security & Risk Analysis
wordpress.org/plugins/wp-showcase-for-githubDisplay Your GitHub Projects on your WordPress website using a simple shortcode. This plugin comes with rich settings page where you can configure eve …
Is WP Showcase for GitHub Safe to Use in 2026?
Generally Safe
Score 85/100WP Showcase for GitHub has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-showcase-for-github' plugin v1.0.0 exhibits a mixed security posture. On the positive side, the plugin has a very small attack surface, with only one shortcode identified and no AJAX handlers, REST API routes, or cron events. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and performing no file operations or external HTTP requests (though one external HTTP request is noted in the signals, which is a contradiction and warrants further investigation). The absence of known vulnerabilities in its history is also a positive indicator.
However, several significant concerns emerge from the static analysis. The most prominent is that 0% of the outputs are properly escaped. This is a critical weakness as it opens the door to Cross-Site Scripting (XSS) vulnerabilities, where an attacker could inject malicious scripts into the plugin's output displayed on a user's website. Additionally, the plugin lacks nonce checks and capability checks entirely, meaning that even though the attack surface is small, any functionality exposed, particularly through the shortcode, is not protected against unauthorized access or manipulation. The lack of taint analysis results (0 flows analyzed) is also a concern, as it implies this type of deeper security check has not been performed, or at least not reported.
Key Concerns
- No output escaping
- Missing nonce checks
- Missing capability checks
- External HTTP requests detected
WP Showcase for GitHub Security Vulnerabilities
WP Showcase for GitHub Code Analysis
Output Escaping
WP Showcase for GitHub Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
WP Showcase for GitHub Maintenance & Trust
Maintenance Signals
Community Trust
WP Showcase for GitHub Alternatives
Github Embed
github-embed
Plugin that allows you to embed details from GitHub just by pasting in the URL as you would any other embed source. Currently supports:
WP Plugin Info Card
wp-plugin-info-card
Plugin Info Card displays plugins & themes data in beautiful cards using WP APIs. Custom plugins, EDD, and GitHub Info Cards are supported.
Static Site Exporter
jekyll-exporter
Features
Pastacode
pastacode
Use Pastacode to add code into your posts with the awesome PrismJs coloration library. So, past'a code!
Embed Block for GitHub
embed-block-for-github
Easily embed GitHub repositories in Gutenberg Editor.
WP Showcase for GitHub Developer Profile
2 plugins · 20 total installs
How We Detect WP Showcase for GitHub
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-showcase-for-github/assets/public/css/ghp-style.css/wp-content/plugins/wp-showcase-for-github/assets/admin/js/ghp-admin.js/wp-content/plugins/wp-showcase-for-github/assets/admin/js/ghp-admin.jswp-showcase-for-github/assets/admin/js/ghp-admin.js?ver=1.0.0HTML / DOM Fingerprints
ghp-repo-wrappersingle-repo-itemrepo-titledata-ghp_columnGHP_PLUGIN_DIR<div class="ghp-repo-wrapper"><div class="row"><div class="col-md-<a href="