EchBay For CocCoc Security & Risk Analysis

wordpress.org/plugins/echbay-for-coccoc

This plugin for user in Vietnam!

0 active installs v1.0.4 PHP + WP 4.8+ Updated Oct 21, 2025
chromefirefoxsafafitrinh-duyet-coc-coc
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EchBay For CocCoc Safe to Use in 2026?

Generally Safe

Score 100/100

EchBay For CocCoc has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "echbay-for-coccoc" plugin version 1.0.4 exhibits a generally strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the presence of nonce and capability checks, even if limited in scope, demonstrates an awareness of basic WordPress security best practices. The plugin also avoids the use of bundled libraries, which can often be a source of outdated and vulnerable code.

However, there are a couple of areas that warrant attention. The single SQL query observed is not using prepared statements, which represents a potential SQL injection risk. While the attack surface is small and the vulnerability history is clean, this single instance of non-prepared SQL introduces a tangible, albeit contained, risk. The percentage of properly escaped output is also moderate, suggesting a potential for cross-site scripting (XSS) vulnerabilities if user-controlled data is involved in the unescaped outputs.

Given the lack of known vulnerabilities and the limited scope of the identified code issues, the overall risk is currently low. The plugin appears to be well-developed from a security perspective, with the exception of the SQL query and the output escaping. Continued vigilance and addressing these minor points would further enhance its security.

Key Concerns

  • SQL query not using prepared statements
  • Moderate output escaping
Vulnerabilities
None known

EchBay For CocCoc Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EchBay For CocCoc Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
4
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

56% escaped9 total outputs
Attack Surface

EchBay For CocCoc Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menueb.php:222
actionwp_footereb.php:228
Maintenance & Trust

EchBay For CocCoc Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 21, 2025
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

EchBay For CocCoc Developer Profile

Dao Quoc Dai

8 plugins · 2K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect EchBay For CocCoc

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/echbay-for-coccoc/style.css/wp-content/plugins/echbay-for-coccoc/guest.html/wp-content/plugins/echbay-for-coccoc/js.js/wp-content/plugins/echbay-for-coccoc/admin.html
Version Parameters
echbay-for-coccoc/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
coccoc-waring-user
HTML Comments
/* Custom CSS *//*body.coccoc-waring-user {padding-top: 0;+3 more
Data Attributes
efc_plugin_urlefc_plugin_versionefc_custom_css_ebnoncestr_position
JS Globals
window.a_lert
FAQ

Frequently Asked Questions about EchBay For CocCoc