
Microformats 2 Security & Risk Analysis
wordpress.org/plugins/wp-uf2Enhances your WordPress theme with Microformats 2 classes.
Is Microformats 2 Safe to Use in 2026?
Generally Safe
Score 85/100Microformats 2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-uf2 plugin v1.1.0 exhibits a strong security posture based on the provided static analysis data. The complete absence of identified entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code shows no signs of dangerous functions, file operations, or external HTTP requests, all of which are positive indicators. The use of prepared statements for all SQL queries is a critical best practice that prevents SQL injection vulnerabilities.
However, the analysis did reveal a concerning lack of output escaping, with 100% of outputs not being properly escaped. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if any of the plugin's outputs are directly influenced by user input without proper sanitization. The absence of nonce and capability checks, while seemingly neutral given the lack of entry points, would become a critical oversight if any new entry points were introduced or if the current lack of entry points is by design and not fully representative of its functionality.
The plugin's vulnerability history is also a positive sign, with no recorded CVEs or past vulnerabilities. This suggests a history of developing secure code. In conclusion, the plugin is well-defended against many common web vulnerabilities due to its limited attack surface and secure SQL handling. The primary and most significant weakness identified is the unescaped output, which warrants immediate attention to mitigate potential XSS risks.
Key Concerns
- Unescaped output detected
Microformats 2 Security Vulnerabilities
Microformats 2 Code Analysis
Output Escaping
Microformats 2 Attack Surface
WordPress Hooks 23
Maintenance & Trust
Microformats 2 Maintenance & Trust
Maintenance Signals
Community Trust
Microformats 2 Alternatives
Micropub
micropub
Allows you to publish to your site using Micropub clients.
MF2 Feeds
mf2-feed
Add Microformats2 Feeds for WordPress
WebSub (FKA. PubSubHubbub)
pubsubhubbub
A WebSub plugin for WordPress that enables real-time publishing and subscription capabilities.
Rich Contact Widget
rich-contact-widget
A simple contact widget enhanced with microdatas & microformats tags for your local SEO
ActivityPub
activitypub
Connect your site to the Open Social Web and let millions of users follow, share, and interact with your content from Mastodon, Pixelfed, and more.
Microformats 2 Developer Profile
5 plugins · 1K total installs
How We Detect Microformats 2
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-uf2/includes/class-uf2-author.php/wp-content/plugins/wp-uf2/includes/class-uf2-comment.php/wp-content/plugins/wp-uf2/includes/class-uf2-media.php/wp-content/plugins/wp-uf2/includes/class-uf2-post.php/wp-content/plugins/wp-uf2/includes/genesis.php