
Cyoud AIO Security & Risk Analysis
wordpress.org/plugins/cyoud-aioExtend, speed up and customize your Wordpress site with Cyoud AIO.
Is Cyoud AIO Safe to Use in 2026?
Generally Safe
Score 85/100Cyoud AIO has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cyoud-aio" plugin version 2.0 presents a significant security risk primarily due to its unprotected AJAX endpoints. While the plugin avoids dangerous functions, raw SQL, file operations, and external HTTP requests, the absence of authentication checks on both AJAX handlers creates a wide attack surface. This means any unauthenticated user could potentially interact with these endpoints, leading to unpredictable behavior or vulnerabilities if the functionality is sensitive. The limited output escaping further exacerbates this risk, as reflected by the 29% proper escaping rate, suggesting that sensitive data might be exposed to Cross-Site Scripting (XSS) attacks through these unprotected entry points. The taint analysis, while not indicating critical or high severity issues, does show flows with unsanitized paths, which in conjunction with unprotected AJAX handlers, can be a pathway for exploitation.
The plugin's vulnerability history is a positive indicator, showing zero recorded CVEs. This suggests that, historically, the plugin has been relatively secure or that vulnerabilities have been promptly addressed. However, the current static analysis findings, particularly the unprotected AJAX handlers and insufficient output escaping, should not be overlooked. The absence of nonce checks and capability checks on these entry points is a critical oversight. In conclusion, while the plugin demonstrates good practices in areas like SQL query preparation and avoiding dangerous functions, the severe lack of authentication and authorization on its primary entry points, combined with poor output sanitization, makes it a high-risk component that requires immediate attention.
Key Concerns
- 2 unprotected AJAX handlers
- Insufficient output escaping (29% proper)
- 2 flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
Cyoud AIO Security Vulnerabilities
Cyoud AIO Code Analysis
Output Escaping
Data Flow Analysis
Cyoud AIO Attack Surface
AJAX Handlers 2
WordPress Hooks 20
Maintenance & Trust
Cyoud AIO Maintenance & Trust
Maintenance Signals
Community Trust
Cyoud AIO Alternatives
Inline Related Posts
intelly-related-posts
Inline Related Posts AUTOMATICALLY inserts related posts INSIDE your content, capturing immediately the reader's attention.
Social Icons Widget & Block – Social Media Icons & Share Buttons
social-icons-widget-by-wpzoom
Social media icons plugin for WordPress - Add 400+ social icons and share buttons. Gutenberg block, widget & Elementor support. GDPR compliant.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
YARPP – Yet Another Related Posts Plugin
yet-another-related-posts-plugin
The best WordPress plugin for displaying related posts. Simple and flexible, with a powerful proven algorithm and inbuilt caching.
Simple Author Box
simple-author-box
Add a responsive author box or guest author box with social icons to any post. Great author box for any site!
Cyoud AIO Developer Profile
2 plugins · 0 total installs
How We Detect Cyoud AIO
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cyoud-aio/css/style.css/wp-content/plugins/cyoud-aio/css/bootstrap.min.css/wp-content/plugins/cyoud-aio/css/cyoud-aio.css/wp-content/plugins/cyoud-aio/js/script.js/wp-content/plugins/cyoud-aio/js/bootstrap.min.js/wp-content/plugins/cyoud-aio/js/custom.jscyoud-aio/style.css?ver=cyoud-aio/script.js?ver=cyoud-aio/bootstrap.min.css?ver=cyoud-aio/bootstrap.min.js?ver=cyoud-aio/custom.js?ver=HTML / DOM Fingerprints
caio_social_iconcaio_si_viewcaio_si_facebookcaio_si_googlecaio_si_twittercaio_si_linkedincaio_si_whatsappdata-target="#cyoud_donate"data-toggle="modal"cyoud_donate_data/wp-json/cyoud-aio/v1/settings[cyoud-aio-donate-button]