Accounting Records Copywriter Security & Risk Analysis

wordpress.org/plugins/accounting-records-copywriter

Упрощение работы администратора с копиратером рерайтером на вашем блоге / Admin’s work simplification with copywriter rewriter for your blog

10 active installs v1.0.0 PHP + WP 4.3+ Updated Dec 9, 2015
bloggercontentcontent-creationcontent-optimizationcopywritercopywriting
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Accounting Records Copywriter Safe to Use in 2026?

Generally Safe

Score 85/100

Accounting Records Copywriter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The accounting-records-copywriter plugin v1.0.0 exhibits a generally strong security posture, with no known historical vulnerabilities. The static analysis reveals a very small attack surface, consisting of a single AJAX handler. Crucially, this AJAX handler appears to have a nonce check, which is a positive security control. The plugin also avoids dangerous functions, file operations, and external HTTP requests, further minimizing potential risks.

However, there are areas for improvement. The output escaping is only properly implemented for 33% of the outputs analyzed, which presents a moderate risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization. Additionally, the taint analysis identified one flow with an unsanitized path, indicating a potential for path traversal or insecure file access, although this was not classified as critical or high severity.

While the plugin's clean vulnerability history is a significant strength, it's important to note that this is the first version. The lack of capability checks on the AJAX handler is a concern, as it means any authenticated user could potentially trigger the AJAX action. The developer should implement capability checks to ensure only authorized users can perform sensitive operations.

Key Concerns

  • Output escaping only 33% proper
  • Taint flow with unsanitized path
  • No capability checks on AJAX handler
Vulnerabilities
None known

Accounting Records Copywriter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Accounting Records Copywriter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
4
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

33% escaped6 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
add_fields_new_user (accounting-records-copywriter.class.php:426)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Accounting Records Copywriter Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_avk_arc_queryaccounting-records-copywriter.class.php:64
WordPress Hooks 21
actionadmin_initaccounting-records-copywriter.class.php:54
filterplugin_row_metaaccounting-records-copywriter.class.php:62
actionpost_updatedaccounting-records-copywriter.class.php:71
actionuser_new_formaccounting-records-copywriter.class.php:73
actionedit_user_profileaccounting-records-copywriter.class.php:74
actionuser_registeraccounting-records-copywriter.class.php:75
actionedit_user_profile_updateaccounting-records-copywriter.class.php:76
actionpersonal_optionsaccounting-records-copywriter.class.php:78
actionadmin_print_scripts-edit.phpaccounting-records-copywriter.class.php:80
actionadmin_print_scripts-users.phpaccounting-records-copywriter.class.php:81
actionadmin_print_scripts-user-new.phpaccounting-records-copywriter.class.php:82
actionadmin_print_scripts-user-edit.phpaccounting-records-copywriter.class.php:83
actionadmin_print_scripts-profile.phpaccounting-records-copywriter.class.php:84
actionuser_row_actionsaccounting-records-copywriter.class.php:86
filtermanage_posts_columnsaccounting-records-copywriter.class.php:87
filtermanage_pages_columnsaccounting-records-copywriter.class.php:88
actionmanage_posts_custom_columnaccounting-records-copywriter.class.php:89
actionmanage_pages_custom_columnaccounting-records-copywriter.class.php:90
actionmanage_users_columnsaccounting-records-copywriter.class.php:91
actionmanage_users_custom_columnaccounting-records-copywriter.class.php:92
actionadmin_footer-profile.phpaccounting-records-copywriter.class.php:283
Maintenance & Trust

Accounting Records Copywriter Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedDec 9, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Accounting Records Copywriter Developer Profile

Smiling_Hemp

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Accounting Records Copywriter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/accounting-records-copywriter/css/style.css/wp-content/plugins/accounting-records-copywriter/js/script.js/wp-content/plugins/accounting-records-copywriter/js/arc-admin.js
Script Paths
/wp-content/plugins/accounting-records-copywriter/js/script.js/wp-content/plugins/accounting-records-copywriter/js/arc-admin.js
Version Parameters
accounting-records-copywriter/css/style.css?ver=accounting-records-copywriter/js/script.js?ver=accounting-records-copywriter/js/arc-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
arc-order-payment
Data Attributes
data-valuedata-user-id
JS Globals
arc_ajax_object
FAQ

Frequently Asked Questions about Accounting Records Copywriter