
codoc Security & Risk Analysis
wordpress.org/plugins/codocA WordPress plugin for monetizing your website with paid articles, Reader Plans, and tipping.
Is codoc Safe to Use in 2026?
Generally Safe
Score 99/100codoc has a strong security track record. Known vulnerabilities have been patched promptly.
The 'codoc' plugin v0.9.58 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and generally performing output escaping, there are significant areas of concern. The presence of an unprotected AJAX handler represents a direct entry point that an attacker could potentially exploit without any authentication or authorization checks, increasing the risk of unauthorized actions or information disclosure. The plugin's vulnerability history includes a past medium-severity CVE related to Cross-site Scripting, indicating a potential weakness in input sanitization or output encoding that, while currently patched, suggests past vulnerabilities and a need for ongoing vigilance.
Overall, the plugin has a moderately good foundation with its handling of SQL and file operations. However, the single unprotected AJAX endpoint is a critical flaw that could be leveraged for malicious purposes. The past XSS vulnerability, even though patched, is a historical indicator that the codebase might have latent vulnerabilities or requires thorough review of its sanitization and escaping mechanisms. The relatively small attack surface is a positive, but the unprotected entry point significantly elevates the risk associated with this plugin.
Key Concerns
- Unprotected AJAX handler found
- Past medium severity XSS vulnerability
codoc Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
codoc <= 0.9.51.12 - Reflected Cross-Site Scripting
codoc Code Analysis
Output Escaping
Data Flow Analysis
codoc Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
codoc Maintenance & Trust
Maintenance Signals
Community Trust
codoc Alternatives
Memberful – Membership Plugin
memberful-wp
Sell memberships and restrict access to content with WordPress and Memberful.
Leaky Paywall
leaky-paywall
The subscription engine for news & niche publishers.
Wallkit Subscriptions & Paywall Plugin for WordPress
wallkit
A Plug & Play paid-content system to manage subscribers, gather fees and drive additional content sales.
Pelcro: Content Subscription Platform
pay-to-view
The #1 Content Subscription Platform. All the tools you need to drive subscription revenue from your audience. Setup a membership paywall in minutes.
Bora Bora
bora-bora
Bora Bora helps you manage and monetize your online community. Protect content, manage memberships and connect your WordPress site to your Bora-Bora.
codoc Developer Profile
1 plugin · 2K total installs
How We Detect codoc
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/codoc/src/css/codoc-editor.css/wp-content/plugins/codoc/src/css/codoc-editor.min.css/wp-content/plugins/codoc/src/css/codoc-free.css/wp-content/plugins/codoc/src/css/codoc-free.min.css/wp-content/plugins/codoc/src/css/codoc-premium.css/wp-content/plugins/codoc/src/css/codoc-premium.min.css/wp-content/plugins/codoc/src/css/codoc-styles.css/wp-content/plugins/codoc/src/css/codoc-styles.min.css+8 morehttps://codoc.jp/js/cms.jshttps://codoc.jp/js/cms-connect.jsHTML / DOM Fingerprints
codoc-theme-rainbow-squaredata-cssdata-connect-codedata-connect-registration-modedata-usercodedata-codoc-idcodoc[codoc]