
Wp Wiki Userprofile Security & Risk Analysis
wordpress.org/plugins/wp-wiki-userprofileThis plugin is used to grab Wikipedia user contribution to wordpress blog.
Is Wp Wiki Userprofile Safe to Use in 2026?
Generally Safe
Score 85/100Wp Wiki Userprofile has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-wiki-userprofile plugin version 1.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and has a history devoid of known vulnerabilities. The attack surface is minimal with only one shortcode entry point, and importantly, no AJAX handlers or REST API routes are exposed without authentication checks. Taint analysis shows no critical or high severity unsanitized paths, suggesting a good effort in preventing direct code execution vulnerabilities.
However, several concerns warrant attention. The use of the `create_function` is a significant red flag, as it can lead to security risks if used with unsanitized input. Furthermore, the plugin has a very low rate of proper output escaping (18%), which opens it up to potential cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without sufficient sanitization. The absence of nonce checks on its single entry point (the shortcode) is also a weakness, making it susceptible to cross-site request forgery (CSRF) attacks. The external HTTP request, while only one, should also be scrutinized for potential vulnerabilities related to insecurely handled external resources.
Overall, while the plugin has a clean vulnerability history and has taken steps towards secure data handling with prepared statements, the presence of `create_function` and inadequate output escaping, coupled with the lack of nonce checks, present tangible security risks. Addressing these specific code-level issues should be prioritized to improve its security.
Key Concerns
- Use of dangerous function create_function
- Low output escaping percentage (18%)
- No nonce checks on entry points
- External HTTP request present
Wp Wiki Userprofile Security Vulnerabilities
Wp Wiki Userprofile Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Wp Wiki Userprofile Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Wp Wiki Userprofile Maintenance & Trust
Maintenance Signals
Community Trust
Wp Wiki Userprofile Alternatives
Wikipedia Anniversaries
wikipedia-anniversaries
Wikipedia Anniversaries is a widget that lets your visitors to see important history dates from Wikipedia.
Wikipedia Widget
wikipedia-widget
Shows a simple Ajax based Wikipedia search-formular and the results for the current post/page title or default keywords.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Wp Wiki Userprofile Developer Profile
2 plugins · 30 total installs
How We Detect Wp Wiki Userprofile
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wrapicon32form-tablesubmitbutton-primaryshortcode-docfeedback-docname="wiki-profile-form"name="codecocktail_wiki_username"name="codecocktail_wiki_user_param"name="wiki-profile-submit"id="icon-options-general"[wikiuser][wikiuser param="editcount"][wikiuser username="xxx" param="editcount"]