
Ejabberd Account Tools Security & Risk Analysis
wordpress.org/plugins/ejabberd-account-toolsProvides a set of useful tools for the ejabberd server, both for the frontend and backend spaces
Is Ejabberd Account Tools Safe to Use in 2026?
Generally Safe
Score 92/100Ejabberd Account Tools has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ejabberd-account-tools v2.11 plugin exhibits several concerning security practices, despite a clean vulnerability history. The most significant risk stems from a substantial attack surface of 17 unprotected REST API routes. This lack of proper authentication and authorization mechanisms on a significant portion of its entry points presents a high likelihood of unauthorized access and manipulation of the plugin's functionalities. Furthermore, the analysis reveals that 0% of its 5 SQL queries utilize prepared statements, indicating a strong potential for SQL injection vulnerabilities if any user-supplied input reaches these queries without adequate sanitization.
While the plugin does not have any recorded CVEs, which is a positive indicator, this should not be relied upon as a sole measure of security. The static analysis strongly suggests inherent weaknesses in its code. The presence of 4 taint flows with unsanitized paths, although not classified as critical or high severity in this analysis, still points to potential risks related to how data is handled. The limited capability checks (0) and the significant percentage of outputs that are not properly escaped (52%) also contribute to a less secure posture. The 3 identified file operations and 3 external HTTP requests, without knowing their context or sanitization, also add to the potential attack surface.
Key Concerns
- Unprotected REST API routes
- Raw SQL queries without prepared statements
- Unescaped output percentage is high
- No capability checks
- Taint flows with unsanitized paths
Ejabberd Account Tools Security Vulnerabilities
Ejabberd Account Tools Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ejabberd Account Tools Attack Surface
REST API Routes 17
Shortcodes 5
WordPress Hooks 34
Scheduled Events 1
Maintenance & Trust
Ejabberd Account Tools Maintenance & Trust
Maintenance Signals
Community Trust
Ejabberd Account Tools Alternatives
XMPP Statistics
xmpp-statistics
Displays the statistics from ejabberd XMPP server through ReST API.
ConverseJS
conversejs
Converse.js is an open source webchat client, that runs in the browser and can be integrated into any website.
P3chat
p3chat
This plugin provides support for p3chat.com online chat service on Your wordpress website.
XMPP Authentication
xmpp-auth
Allows users to authenticate without password via XMPP and for visitors to be filtered by XMPP verification.
Custom Google Talk Chatback
custom-google-talk-chatback
Easily embed Goole Talk Chatback on your site for online chat support. Widget, Shortcode and Template Tag support!
Ejabberd Account Tools Developer Profile
7 plugins · 420 total installs
How We Detect Ejabberd Account Tools
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ejabberd-account-tools/css/style.min.css/wp-content/plugins/ejabberd-account-tools/js/js.ejabat.form.min.js/wp-content/plugins/ejabberd-account-tools/js/js.ejabat.form.min.jsejabberd-account-tools/css/style.min.css?ver=ejabberd-account-tools/js/js.ejabat.form.min.js?ver=HTML / DOM Fingerprints
ejabat-spinnerejabat-loaderejabat-infoejabat-errorejabat-successejabat-blockedejabat-validateejabat-tipdata-action="change-email-form"data-action="change-email"ejabat/wp-json/ejabberd-account-tools/v1/<p data-action="change-email-form" class="ejabat"><span class="ejabat-loader" title="