
wpCiteULike Security & Risk Analysis
wordpress.org/plugins/wpciteulikewpciteulike enables to add a bibliography maintained with CiteULike formatted as HTML to wordpress pages and posts. The input data is the bibtex meta …
Is wpCiteULike Safe to Use in 2026?
Generally Safe
Score 85/100wpCiteULike has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wpciteulike v0.7.1 plugin exhibits a mixed security posture. While it has a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries utilize prepared statements, there are significant concerns. The most alarming finding is the presence of 12 instances of the 'unserialize' function, which is a known vector for remote code execution if used with untrusted input. Compounding this is the complete absence of output escaping for all 26 identified outputs, meaning any data outputted by the plugin is vulnerable to cross-site scripting (XSS) attacks. Furthermore, the plugin lacks any nonce or capability checks, leaving its entry points (though currently zero) unprotected if they were to emerge. The vulnerability history is clean, with no recorded CVEs, which is positive but could also indicate a lack of rigorous security auditing or that past vulnerabilities were patched thoroughly. However, the static analysis reveals a high risk due to the combination of dangerous function usage without proper sanitization and universally unescaped output. The lack of any taint flows analyzed is also a weakness, as it implies a limited scope of security testing.
Key Concerns
- 12 instances of 'unserialize' function used
- 0% of outputs properly escaped
- No nonce checks implemented
- No capability checks implemented
- Limited or no taint analysis performed
wpCiteULike Security Vulnerabilities
wpCiteULike Code Analysis
Dangerous Functions Found
Output Escaping
wpCiteULike Attack Surface
WordPress Hooks 8
Maintenance & Trust
wpCiteULike Maintenance & Trust
Maintenance Signals
Community Trust
wpCiteULike Alternatives
bib3html
bib3html
bib3html is a refined fork from bib2html written by tango. It enables to add bibtex entries formatted as HTML in wordpress pages and posts.
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
Advanced Excerpt
advanced-excerpt
Control the appearance of WordPress post excerpts
Advanced Image Styles
advanced-image-styles
Adjust an image's margins and border with ease in the Visual editor.
Raw HTML
raw-html
Lets you use raw HTML or any other code in your posts. You can also disable smart quotes and other automatic formatting on a per-post basis.
wpCiteULike Developer Profile
1 plugin · 10 total installs
How We Detect wpCiteULike
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpciteulike/css/style.css/wp-content/plugins/wpciteulike/js/wpciteulike.jswpciteulike/css/style.css?ver=wpciteulike/js/wpciteulike.js?ver=HTML / DOM Fingerprints
citeulike-widget<!-- wpciteulike_start --><!-- wpciteulike_end -->data-citeulike-targetwpCiteULikewpciteulike[citeulike][citeulike-widget]