Elimina Diacritice Security & Risk Analysis

wordpress.org/plugins/elimina-diacritice

Elimina fara efort semnele cu diacritice din textele in limba romana adaugate prin editorul de text wordpress.

30 active installs v1.1.0 PHP + WP 4.0+ Updated Feb 25, 2024
diacriticeelimina-diacriticescoate-diacritice
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Elimina Diacritice Safe to Use in 2026?

Generally Safe

Score 85/100

Elimina Diacritice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "elimina-diacritice" plugin version 1.1.0 exhibits a generally strong security posture based on the static analysis provided. The absence of known CVEs and a clean vulnerability history are positive indicators. The plugin also scores well on several good security practices, including zero dangerous functions, SQL queries exclusively using prepared statements, no file operations, and no external HTTP requests. However, a significant concern arises from the fact that 100% of the identified output operations are not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if the output is user-controllable and displayed without proper sanitization.

While the attack surface is reported as zero entry points, this assessment seems to be based on the absence of explicitly defined AJAX handlers, REST API routes, shortcodes, and cron events. The lack of nonce and capability checks across all identified entry points is a significant weakness. If any unexpected or implicit entry points exist, they would be entirely unprotected. The taint analysis showing zero flows is also positive, but this could be less meaningful if the plugin has a very limited scope and minimal interaction with external data. Overall, the plugin demonstrates good development hygiene in some areas but has critical gaps in output sanitization and authorization checks that require immediate attention.

Key Concerns

  • Output escaping is not properly implemented
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Elimina Diacritice Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Elimina Diacritice Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Elimina Diacritice Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitelimina-diacritice.php:35
actionadmin_enqueue_scriptselimina-diacritice.php:36
actionelementor/editor/before_enqueue_scriptselimina-diacritice.php:37
actionmedia_buttonselimina-diacritice.php:38
Maintenance & Trust

Elimina Diacritice Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 25, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Elimina Diacritice Developer Profile

perfectpixelro

1 plugin · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Elimina Diacritice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elimina-diacritice/js/admin.js
Script Paths
/wp-content/plugins/elimina-diacritice/js/admin.js
Version Parameters
elimina-diacritice/js/admin.js?ver=1.1.0

HTML / DOM Fingerprints

CSS Classes
wpedr_button
JS Globals
WPEDRData
Shortcode Output
<a href="#" class="button" id="wpedr_button" aria-label="Elimina Diacritice">Elimina Diacritice</a>
FAQ

Frequently Asked Questions about Elimina Diacritice