
ZMOOZ Web Stories Security & Risk Analysis
wordpress.org/plugins/zmooz-storiesZMOOZ Stories is a solution that allows publishers and bloggers to automatically transform their articles into Web Story format.
Is ZMOOZ Web Stories Safe to Use in 2026?
Generally Safe
Score 85/100ZMOOZ Web Stories has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zmooz-stories plugin exhibits several concerning security practices, particularly regarding its attack surface. With all three identified REST API entry points lacking permission callbacks, there's a significant risk of unauthorized access and manipulation of plugin functionality. While the plugin shows good practices in SQL query preparation and output escaping, the presence of two unsanitized path flows in taint analysis, even without critical severity, suggests a potential for directory traversal or file manipulation vulnerabilities. The complete absence of nonce checks and a single capability check further amplifies the risk associated with its unprotected entry points. The plugin's history of zero known vulnerabilities is a positive sign, suggesting that it might not have been a frequent target or that previous versions were more robust. However, this historical data should not overshadow the immediate risks identified in the current static analysis.
Key Concerns
- REST API routes without permission callbacks
- Flows with unsanitized paths (taint analysis)
- Missing nonce checks
- Limited capability checks
ZMOOZ Web Stories Security Vulnerabilities
ZMOOZ Web Stories Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ZMOOZ Web Stories Attack Surface
REST API Routes 3
WordPress Hooks 17
Maintenance & Trust
ZMOOZ Web Stories Maintenance & Trust
Maintenance Signals
Community Trust
ZMOOZ Web Stories Alternatives
Web Stories
web-stories
Web Stories are a visual storytelling format for the open web which immerses your readers in fast-loading, full-screen, and visually rich experiences.
Web Stories Enhancer – Level Up Your Web Stories
web-stories-enhancer
This is the Web Stories Enhancer Plugin for showing the web stories to the website with the help of a shortcode [web_stories_enhancer].
Web Stories Widgets For Elementor
shortcodes-for-amp-web-stories-and-elementor-widget
This addon will helps you to easily represent Google Web stories in the Page/Post using Elementor Widget and shortcodes.
MakeStories (for Google Web Stories)
makestories-helper
MakeStories helper plugin to publish stories for your WordPress site
My Story
my-story
Create your own custom Instagram style stories. ✌
ZMOOZ Web Stories Developer Profile
1 plugin · 10 total installs
How We Detect ZMOOZ Web Stories
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zmooz-stories/build/index.js/wp-content/plugins/zmooz-stories/build/index.css/wp-content/plugins/zmooz-stories/assets/css/styles.css/wp-content/plugins/zmooz-stories/build/index.jszmooz-stories/build/index.js?ver=zmooz-stories/build/index.css?ver=HTML / DOM Fingerprints
zmooz_settings_switchzmooz_settings_sliderzmooz_settings_round---------------BEGIN--------------// ZMOOZ WEB STORIES PLUGIN By Prince Nick BALLO1/06/2022zmooz_custom_plugin_default_userZMOOZ_APIZMOOZ_USED_DOMAINZMOOZ_USER_AUTH_TOKENZMOOZ_POST_TYPE/wp-json/zmooz-stories-plugin/v1/new-story//wp-json/zmooz-stories-plugin/v1/update-story/wp-json/zmooz-stories-plugin/v1/checkup