All Path Messaging Security & Risk Analysis

wordpress.org/plugins/all-path-messaging

Limitless Communication: All-in-one, super scalable, messaging Solution for WordPress.

0 active installs v1.0.0 PHP 5.6+ WP 4.4+ Updated Oct 27, 2024
emailmessagingpush-notificationsms
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is All Path Messaging Safe to Use in 2026?

Generally Safe

Score 92/100

All Path Messaging has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'all-path-messaging' plugin version 1.0.0 demonstrates a strong security posture based on the provided static analysis. The complete absence of exposed entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, all identified SQL queries utilize prepared statements, and all output operations are properly escaped, indicating good coding practices for preventing common web vulnerabilities. The presence of nonce checks, even without explicit capability checks on every entry point (though there are no unprotected entry points), is a positive sign of security awareness.

However, the lack of capability checks on any entry points, coupled with the absence of any entry points to check against, means that if any were to be introduced in future versions without proper authentication and authorization, the plugin would be inherently vulnerable. The bundled libraries, Guzzle and PHPMailer, are potential areas of concern if they are outdated or contain known vulnerabilities. The absence of any recorded vulnerability history is a strong indicator of past secure development, but it's important to note that this does not guarantee future immunity.

In conclusion, 'all-path-messaging' v1.0.0 appears to be a securely developed plugin with a minimal attack surface and good internal coding practices. The primary potential weakness lies in the unknown status of bundled libraries and the inherent risk if new entry points are added in future versions without robust authentication and authorization mechanisms.

Key Concerns

  • No capability checks on entry points
  • Bundled libraries (Guzzle, PHPMailer) may be outdated
Vulnerabilities
None known

All Path Messaging Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

All Path Messaging Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

All Path Messaging Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
75 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

GuzzlePHPMailer

Output Escaping

100% escaped75 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
options_page (inc/email/class-admin.php:43)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

All Path Messaging Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_menuinc/class-admin.php:45
filterall_path_servicesinc/email/namespace.php:74
filterpre_wp_mailinc/email/wp-mail/namespace.php:26
actioninitinc/namespace.php:63
filterall_path_servicesinc/sms/namespace.php:69
Maintenance & Trust

All Path Messaging Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedOct 27, 2024
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

All Path Messaging Developer Profile

Souptik Datta

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All Path Messaging

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/all-path-messaging/css/style.css/wp-content/plugins/all-path-messaging/js/script.js
Script Paths
/wp-content/plugins/all-path-messaging/js/script.js
Version Parameters
all-path-messaging/style.css?ver=all-path-messaging/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about All Path Messaging