WP WDFY Integration of Wodify Security & Risk Analysis

wordpress.org/plugins/wp-wdfy-integration-of-wodify

Display Wodify information directly within your Wordpress blog.

100 active installs v4.11 PHP 5.6+ WP 4.6+ Updated Apr 30, 2025
crossfitwodify
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP WDFY Integration of Wodify Safe to Use in 2026?

Generally Safe

Score 92/100

WP WDFY Integration of Wodify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wp-wdfy-integration-of-wodify" plugin version 4.11 presents a generally positive security posture based on the provided static analysis. The absence of unprotected entry points (AJAX, REST API, shortcodes, cron events) is a significant strength. The plugin also demonstrates good practice by including capability checks on its four REST API routes. The lack of dangerous functions identified and zero critical or high severity taint flows further contributes to a reassuring initial assessment.

However, there are areas for concern. The most significant is the presence of SQL queries that are not using prepared statements, indicating a potential risk of SQL injection vulnerabilities. Furthermore, a low percentage of output escaping (28%) is a considerable weakness, suggesting that stored or reflected cross-site scripting (XSS) vulnerabilities could be present, especially if dynamic data is not properly sanitized before being outputted. The complete absence of nonce checks on the identified entry points is also a notable gap, potentially leaving the plugin susceptible to cross-site request forgery (CSRF) attacks.

The plugin's vulnerability history is clean, with no recorded CVEs. This is a strong positive indicator, suggesting a proactive approach to security or simply a lack of discovered vulnerabilities to date. However, it's important to note that a clean history does not guarantee future security, and the identified code weaknesses, particularly the unescaped output and raw SQL, should be addressed proactively to maintain this positive track record.

Key Concerns

  • SQL queries not using prepared statements
  • Low percentage of output escaping
  • No nonce checks on entry points
Vulnerabilities
None known

WP WDFY Integration of Wodify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP WDFY Integration of Wodify Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

WP WDFY Integration of Wodify Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
204
80 escaped
Nonce Checks
0
Capability Checks
4
File Operations
2
External Requests
5
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

28% escaped284 total outputs
Attack Surface

WP WDFY Integration of Wodify Attack Surface

Entry Points7
Unprotected0

REST API Routes 4

GETPOST/wp-json/wp-integration-of-wodify/v1/lookups/blocks.php:124
GETPOST/wp-json/wp-integration-of-wodify/v1/blockwod/blocks.php:133
GETPOST/wp-json/wp-integration-of-wodify/v1/blockevents/blocks.php:142
GETPOST/wp-json/wp-integration-of-wodify/v1/wod-alexa/date=(?P<date>[a-zA-Z0-9-]+)/program=(?P<program>[a-zA-Z0-9-]+)/speakmode=(?P<speakmode>[01])/password=(?P<password>[0-9]+)restapi.php:7

Shortcodes 3

[wdfyevents] shortcodes.php:58
[wdfywod] shortcodes.php:127
[wdfylink] shortcodes.php:226
WordPress Hooks 17
filterblock_categories_allblocks.php:4
actioninitblocks.php:76
actionrest_api_initblocks.php:123
actionrest_api_initblocks.php:132
actionrest_api_initblocks.php:141
actionwp_footerfunctions\functions.php:21
actionbefore_delete_postfunctions\functions.php:375
actionrest_api_initrestapi.php:6
actionwdfy_cron_wodpublishsoswodify.php:111
actionwdfy_cron_cache_classessoswodify.php:142
actionadmin_menusoswodify.php:154
actionadmin_initsoswodify.php:155
actionadmin_enqueue_scriptssoswodify.php:158
actionplugins_loadedsoswodify.php:163
actionwidgets_initsoswodify.php:164
actionwp_enqueue_scriptssoswodify.php:165
filtercron_schedulessoswodify.php:166

Scheduled Events 2

wdfy_cron_cache_classes
wdfy_cron_wodpublish
Maintenance & Trust

WP WDFY Integration of Wodify Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 30, 2025
PHP min version5.6
Downloads10K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

WP WDFY Integration of Wodify Developer Profile

osti47

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP WDFY Integration of Wodify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-wdfy-integration-of-wodify/css/style.css/wp-content/plugins/wp-wdfy-integration-of-wodify/js/colorpicker.js/wp-content/plugins/wp-wdfy-integration-of-wodify/css/admin.css
Script Paths
/wp-content/plugins/wp-wdfy-integration-of-wodify/js/colorpicker.js
Version Parameters
wp-wdfy-integration-of-wodify/css/style.css?ver=wp-wdfy-integration-of-wodify/js/colorpicker.js?ver=wp-wdfy-integration-of-wodify/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
wodify_wod_widgetwodify_classes_widget
HTML Comments
TODO ideas
FAQ

Frequently Asked Questions about WP WDFY Integration of Wodify