Plugin inspection:

Ajax Pagination (twitter Style)

Potentially unsafe

Last revised:

Confidence: Medium
This plugin has been given a short, targeted code review.

Before using this plugin, you should very carefully consider its potential problems and should conduct a thorough assessment. Read more about this recommendation.

Warnings

The version of this plugin that this recommendation was based on is known to be vulnerable to attack:

Findings

This plugin contains a file inclusion vulnerability that is exploitable by an unauthenticated user. It does not appear to have any mechanism to upload malicious code, so is not vulnerable in isolation. However, many other plugins do have vulnerabilities that would allow files to be uploaded or modified. Use of this plugin should therefore be considered very carefully.

Reason for the 'Potentially unsafe' result

The plugin contains or is likely to contain a vulnerability which could be exploited by an end user and which would compromise the site’s confidentiality, integrity or availability:

Failure criteria

  • Lack of input sanitisation
  • Unsafe file or network IO

Read more about our failure criteria.