Findings
- The plugin does not escape its output. This allows WordPress users who do not have the “unfiltered_html” capability to insert JavaScript. By default only Admins on single sites, and Super Admins on Multisite have the unfiltered_html capability.
Reason for the 'Use with caution' result
The plugin contains or is likely to contain a vulnerability which could be exploited by a privileged user to affect the site’s confidentiality, integrity or availability in a manner exceeding their privileges:
Does not properly escape output.