
WP WDFY Integration of Wodify Security & Risk Analysis
wordpress.org/plugins/wp-wdfy-integration-of-wodifyDisplay Wodify information directly within your Wordpress blog.
Is WP WDFY Integration of Wodify Safe to Use in 2026?
Generally Safe
Score 92/100WP WDFY Integration of Wodify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-wdfy-integration-of-wodify" plugin version 4.11 presents a generally positive security posture based on the provided static analysis. The absence of unprotected entry points (AJAX, REST API, shortcodes, cron events) is a significant strength. The plugin also demonstrates good practice by including capability checks on its four REST API routes. The lack of dangerous functions identified and zero critical or high severity taint flows further contributes to a reassuring initial assessment.
However, there are areas for concern. The most significant is the presence of SQL queries that are not using prepared statements, indicating a potential risk of SQL injection vulnerabilities. Furthermore, a low percentage of output escaping (28%) is a considerable weakness, suggesting that stored or reflected cross-site scripting (XSS) vulnerabilities could be present, especially if dynamic data is not properly sanitized before being outputted. The complete absence of nonce checks on the identified entry points is also a notable gap, potentially leaving the plugin susceptible to cross-site request forgery (CSRF) attacks.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a strong positive indicator, suggesting a proactive approach to security or simply a lack of discovered vulnerabilities to date. However, it's important to note that a clean history does not guarantee future security, and the identified code weaknesses, particularly the unescaped output and raw SQL, should be addressed proactively to maintain this positive track record.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of output escaping
- No nonce checks on entry points
WP WDFY Integration of Wodify Security Vulnerabilities
WP WDFY Integration of Wodify Release Timeline
WP WDFY Integration of Wodify Code Analysis
SQL Query Safety
Output Escaping
WP WDFY Integration of Wodify Attack Surface
REST API Routes 4
Shortcodes 3
WordPress Hooks 17
Scheduled Events 2
Maintenance & Trust
WP WDFY Integration of Wodify Maintenance & Trust
Maintenance Signals
Community Trust
WP WDFY Integration of Wodify Developer Profile
1 plugin · 100 total installs
How We Detect WP WDFY Integration of Wodify
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-wdfy-integration-of-wodify/css/style.css/wp-content/plugins/wp-wdfy-integration-of-wodify/js/colorpicker.js/wp-content/plugins/wp-wdfy-integration-of-wodify/css/admin.css/wp-content/plugins/wp-wdfy-integration-of-wodify/js/colorpicker.jswp-wdfy-integration-of-wodify/css/style.css?ver=wp-wdfy-integration-of-wodify/js/colorpicker.js?ver=wp-wdfy-integration-of-wodify/css/admin.css?ver=HTML / DOM Fingerprints
wodify_wod_widgetwodify_classes_widgetTODO ideas