
WWI Blogcard Security & Risk Analysis
wordpress.org/plugins/wwi-blogcardA WordPress block plugin that generates beautiful blog cards from URLs using OGP information.
Is WWI Blogcard Safe to Use in 2026?
Generally Safe
Score 100/100WWI Blogcard has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wwi-blogcard' plugin v1.0.11 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the consistent use of prepared statements for all SQL queries, and the 100% proper output escaping are all excellent security practices. Furthermore, the presence of nonce and capability checks, along with no recorded vulnerabilities in its history, suggests a well-maintained and secure plugin. The limited attack surface with no identified unprotected entry points is also a positive indicator.
However, there are a few minor points to consider. The plugin makes one external HTTP request, which, while not inherently a vulnerability, could be a potential vector if not handled securely or if the external service is compromised. The lack of taint analysis results (zero flows analyzed) means that while no issues were found, there's no active confirmation of the sanitization of data flows.
In conclusion, 'wwi-blogcard' v1.0.11 appears to be a secure plugin with robust coding practices. The main areas for attention are the single external HTTP request and the absence of taint analysis results, which, while not critical flaws based on the data, represent potential areas for further scrutiny in a broader security audit. The plugin's history of zero vulnerabilities is a significant strength.
Key Concerns
- External HTTP request made by the plugin
- No taint analysis flows analyzed
WWI Blogcard Security Vulnerabilities
WWI Blogcard Code Analysis
SQL Query Safety
Output Escaping
WWI Blogcard Attack Surface
WordPress Hooks 8
Maintenance & Trust
WWI Blogcard Maintenance & Trust
Maintenance Signals
Community Trust
WWI Blogcard Alternatives
Simple Link Embed
simple-link-embed
Create beautiful blog cards by simply entering a URL. Automatically fetches OGP data and displays stylish link previews in the block editor.
Pz-LinkCard
pz-linkcard
This plugin is intended to display a link in a blog card format. The goodbye to the text-only link.
Simple Blog Card
simple-blog-card
Get OGP and display blog card.
Pz-HatenaBlogCard
pz-hatenablogcard
This plug-in to display a link in the article by using the "Hatena blog card".
SU Blocks Blogcard
blogcard-for-wp
A WordPress plugin that makes it easy to create blog cards. Simply enter a URL and automatically fetch metadata to display beautiful cards.
WWI Blogcard Developer Profile
1 plugin · 0 total installs
How We Detect WWI Blogcard
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wwi-blogcard/build/wwi-blogcard.asset.php/wp-content/plugins/wwi-blogcard/build/index.jswwi-blogcard/style.css?ver=wwi-blogcard/index.js?ver=HTML / DOM Fingerprints
data-wwi-blogcard-urlwindow.wwiBlogcardSettings/wp-json/wwi-blogcard/v1/fetch/wp-json/wwi-blogcard/v1/clear-cache