Easy Video Call [GWE] Security & Risk Analysis

wordpress.org/plugins/easy-video-call

Easy Video Call is a simple plugin for making video call easily. To display the video call option simply add this [easy-video-call] shortcode inside y …

50 active installs v2.0.2 PHP 7.0+ WP 4.7+ Updated Jul 22, 2025
agorachatlivechatvideo-callvideochat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Video Call [GWE] Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Video Call [GWE] has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "easy-video-call" plugin v2.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and has a high percentage of properly escaped output. The absence of dangerous functions, file operations, external HTTP requests, and known historical vulnerabilities further contributes to a seemingly stable codebase. However, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers, both of which lack any form of authentication or capability checks. This represents a critical weakness, as these handlers could potentially be triggered by unauthenticated users, leading to unintended actions or information disclosure. The absence of taint analysis data and a lack of critical or high severity vulnerabilities in its history, while positive, cannot entirely mitigate the risk posed by these unprotected entry points. The plugin's strengths lie in its code hygiene for common vulnerability areas, but its unprotected AJAX handlers present a clear and present risk that requires immediate attention.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
Vulnerabilities
None known

Easy Video Call [GWE] Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easy Video Call [GWE] Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
35 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped37 total outputs
Attack Surface
2 unprotected

Easy Video Call [GWE] Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_evc_generate_agora_tokeneasy-video-call.php:46
noprivwp_ajax_evc_generate_agora_tokeneasy-video-call.php:47

Shortcodes 1

[easy-video-call] easy-video-call.php:48
WordPress Hooks 8
actionplugins_loadedeasy-video-call.php:43
actionwp_enqueue_scriptseasy-video-call.php:44
actionadmin_enqueue_scriptseasy-video-call.php:45
actionwp_footereasy-video-call.php:49
actionadmin_initeasy-video-call.php:50
actionadmin_menueasy-video-call.php:198
actionadmin_initeasy-video-call.php:199
actionadmin_initeasy-video-call.php:200
Maintenance & Trust

Easy Video Call [GWE] Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 22, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

Easy Video Call [GWE] Developer Profile

Mukul Hossain

4 plugins · 150 total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Video Call [GWE]

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-video-call/assets/admin/css/admin.css/wp-content/plugins/easy-video-call/assets/public/css/evcmain.css/wp-content/plugins/easy-video-call/assets/public/css/all.min.css/wp-content/plugins/easy-video-call/assets/public/css/fontawesome.min.css/wp-content/plugins/easy-video-call/evc-color-picker-script.js/wp-content/plugins/easy-video-call/assets/public/js/AgoraRTC_N-latest.js/wp-content/plugins/easy-video-call/assets/public/js/evcmain.js
Script Paths
/wp-content/plugins/easy-video-call/evc-color-picker-script.js/wp-content/plugins/easy-video-call/assets/public/js/AgoraRTC_N-latest.js/wp-content/plugins/easy-video-call/assets/public/js/evcmain.js
Version Parameters
easy-video-call/assets/admin/css/admin.css?ver=easy-video-call/assets/public/css/evcmain.css?ver=easy-video-call/assets/public/css/all.min.css?ver=easy-video-call/assets/public/css/fontawesome.min.css?ver=easy-video-call/evc-color-picker-script.js?ver=easy-video-call/assets/public/js/AgoraRTC_N-latest.js?ver=easy-video-call/assets/public/js/evcmain.js?ver=

HTML / DOM Fingerprints

CSS Classes
evc-video-call
Data Attributes
evc-primaryevc-whiteevc-transparentevc-red
JS Globals
evc_config
REST Endpoints
/wp-json/evc/v1/token
Shortcode Output
[easy-video-call]
FAQ

Frequently Asked Questions about Easy Video Call [GWE]