X3P0: Progress Security & Risk Analysis

wordpress.org/plugins/x3p0-progress

A customizable progress bar block to visually track completion toward any percentage, numeric, financial, or unit-based goal.

30 active installs v2.0.2 PHP 8.1+ WP 6.8+ Updated Feb 24, 2026
blockblocksgutenbergprogress
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is X3P0: Progress Safe to Use in 2026?

Generally Safe

Score 100/100

X3P0: Progress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The static analysis of the "x3p0-progress" plugin version 2.0.2 reveals an exceptionally clean codebase with no identified attack surface points like AJAX handlers, REST API routes, shortcodes, or cron events. The plugin also demonstrates strong secure coding practices, with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. Furthermore, there are no file operations, external HTTP requests, or indications of missing nonce or capability checks within the analyzed code. The taint analysis also shows no identified vulnerabilities.

The vulnerability history for this plugin is entirely empty, with no recorded CVEs of any severity. This suggests a history of security diligence or a lack of targeted exploitation. However, the complete absence of any entry points, coupled with zero recorded vulnerabilities and a lack of bundled libraries, could also indicate a very limited or possibly non-functional plugin that might not be actively used or tested in real-world scenarios. Therefore, while the current analysis points to a secure implementation of its (unknown) functionality, the lack of observed activity might mask potential future issues or the consequences of its absence.

Vulnerabilities
None known

X3P0: Progress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

X3P0: Progress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

X3P0: Progress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionplugins_loadedplugin.php:21
actioninitsrc\Block\BlockRegistrar.php:37
Maintenance & Trust

X3P0: Progress Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 24, 2026
PHP min version8.1
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

X3P0: Progress Developer Profile

Justin Tadlock

33 plugins · 34K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect X3P0: Progress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/x3p0-progress/public/blocks/build/view.asset.php
Script Paths
/wp-content/plugins/x3p0-progress/public/blocks/build/view.js
Version Parameters
x3p0-progress/public/blocks/build/view.asset.php?ver=

HTML / DOM Fingerprints

JS Globals
x3p0Progress
FAQ

Frequently Asked Questions about X3P0: Progress