Copy Compass Security & Risk Analysis

wordpress.org/plugins/copy-compass

Copy Compass automatically analyses your posts or pages to SEO best practices.

10 active installs v1.4.2 PHP + WP 2.9.2+ Updated Oct 20, 2010
content-analysiscopy-compasscopy-writingcopywritingseo
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Copy Compass Safe to Use in 2026?

Generally Safe

Score 85/100

Copy Compass has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The 'copy-compass' v1.4.2 plugin exhibits a generally good security posture, particularly in its minimal attack surface and the complete absence of known vulnerabilities. The static analysis indicates a robust approach to database interactions, with all SQL queries utilizing prepared statements, significantly mitigating the risk of SQL injection. The presence of nonce and capability checks, albeit limited, demonstrates an awareness of authentication and authorization best practices.

However, a significant concern arises from the output escaping. The static analysis reveals that 0% of the 8 identified outputs are properly escaped. This is a critical flaw that could lead to cross-site scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website if any user-generated or dynamic content is displayed without proper sanitization. Furthermore, the taint analysis identified one flow with an unsanitized path, suggesting a potential risk related to file operations or external requests, although it was not classified as critical or high severity.

While the plugin has no recorded vulnerability history, which is a positive indicator, the identified issues in output escaping and path sanitization warrant attention. The lack of proper output escaping is a common vector for XSS attacks and should be addressed immediately. The strength of this plugin lies in its limited attack surface and secure database practices, but the identified output sanitization and path handling weaknesses present a clear risk that needs mitigation.

Key Concerns

  • No output escaping
  • Unsanitized paths found in taint analysis
Vulnerabilities
None known

Copy Compass Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Copy Compass Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Copy Compass Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
1
Capability Checks
2
File Operations
3
External Requests
2
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
cc_menu_layout (article-analyser.php:211)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Copy Compass Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_menuarticle-analyser.php:13
actionadmin_headarticle-analyser.php:14
actionadmin_noticesarticle-analyser.php:15
actioninitarticle-analyser.php:16
actionsave_postarticle-analyser.php:17
actionadmin_menuarticle-analyser.php:18
actionadmin_noticesarticle-analyser.php:19
actiondbx_post_advancedarticle-analyser.php:178
actiondbx_page_advancedarticle-analyser.php:179
Maintenance & Trust

Copy Compass Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedOct 20, 2010
PHP min version
Downloads6K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

Copy Compass Developer Profile

NickDuncan

5 plugins · 490 total installs

81
trust score
Avg Security Score
81/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Copy Compass

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/copy-compass/includes/cFKre.php/wp-content/plugins/copy-compass/display.php/wp-content/plugins/copy-compass/includes/generate-api.php

HTML / DOM Fingerprints

CSS Classes
cc_overlay_bgcc_overlaycc_menucc_overlay_contentcc_btnaa_loadercc_register_btncc_register_box+4 more
Data Attributes
id="cc_btn"id="cc_register_btn"id="cc_register_api"id="cc_overlay_bg"id="cc_overlay"id="cc_menu"+6 more
JS Globals
cc_add_custom_boxcc_headcc_overlaycc_load_jquerycc_save_postdatacc_admin_menu+4 more
FAQ

Frequently Asked Questions about Copy Compass